자바스크립트로 실행되는 Appleseed v2.1

2022-08-26 Secu I Appleseed v2.1 running with JavaScript

https://stic.secui.com/main/main/threatInfo?id=69

Appleseed v2.1 was delivered through a JavaScript loader disguised with a decoy document, double Base64-encoded payloads, and string-splitting obfuscation to evade detection. The loader drops an encoded Appleseed DLL under ProgramData, decodes it with certutil, and executes it through Regsvr32 before contacting C2 for additional scripts. Version 2.1 changes the malware’s string decryption from the older XOR-based routine to arithmetic operations over hex byte data and adds system information collection. The malware gathers host, antivirus, program, Recent, Desktop, Downloads, and Documents data, encrypts command output and files with ZIP, RC4, RSA, and XOR layers, and uses PDF-like headers before exfiltration. The report lists C2 domains including netra.atwebpages[.]com, update.hannarng.kro[.]kr, and update.modernmap.n-e[.]kr, with detection naming it Trojan.RAT.Kimsuky.Appleseed.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8ab2d48467440eb17fd971386f845a1… 2022-08-26 2022-08-26
HASH 593124155a1bb27b0b8b7d67149e60c… 2022-08-26 2022-08-26
HASH f18c89a434215a99b4949768ace67ea… 2022-08-26 2022-08-26
HASH bce769212f906ff3edecee4eea8de51… 2022-08-26 2022-08-26
HASH e7e2b29e310bb693139e13cfaad732a… 2022-08-26 2022-08-26
HASH 69059dd931f3b5d44a722c6d1e3b60a… 2022-08-26 2022-08-26
HASH 0de3202c4808cbb6213fc0d316039b8… 2022-08-26 2022-08-26
HASH 4bb78bd5f07638b334e135623c44d12… 2022-08-26 2022-08-26
DOMAIN update.hannarng.kro.kr 2022-08-26 2022-08-26
DOMAIN netra.atwebpages.com 2022-08-26 2022-08-26
DOMAIN update.modernmap.n-e.kr 2022-08-26 2022-08-26

Related Reports

« Back