자바스크립트로 실행되는 Appleseed v2.1
2022-08-26 • Secu I • Appleseed v2.1 running with JavaScript •
Appleseed v2.1 was delivered through a JavaScript loader disguised with a decoy document, double Base64-encoded payloads, and string-splitting obfuscation to evade detection. The loader drops an encoded Appleseed DLL under ProgramData, decodes it with certutil, and executes it through Regsvr32 before contacting C2 for additional scripts. Version 2.1 changes the malware’s string decryption from the older XOR-based routine to arithmetic operations over hex byte data and adds system information collection. The malware gathers host, antivirus, program, Recent, Desktop, Downloads, and Documents data, encrypts command output and files with ZIP, RC4, RSA, and XOR layers, and uses PDF-like headers before exfiltration. The report lists C2 domains including netra.atwebpages[.]com, update.hannarng.kro[.]kr, and update.modernmap.n-e[.]kr, with detection naming it Trojan.RAT.Kimsuky.Appleseed.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8ab2d48467440eb17fd971386f845a1… | 2022-08-26 | 2022-08-26 |
| HASH | 593124155a1bb27b0b8b7d67149e60c… | 2022-08-26 | 2022-08-26 |
| HASH | f18c89a434215a99b4949768ace67ea… | 2022-08-26 | 2022-08-26 |
| HASH | bce769212f906ff3edecee4eea8de51… | 2022-08-26 | 2022-08-26 |
| HASH | e7e2b29e310bb693139e13cfaad732a… | 2022-08-26 | 2022-08-26 |
| HASH | 69059dd931f3b5d44a722c6d1e3b60a… | 2022-08-26 | 2022-08-26 |
| HASH | 0de3202c4808cbb6213fc0d316039b8… | 2022-08-26 | 2022-08-26 |
| HASH | 4bb78bd5f07638b334e135623c44d12… | 2022-08-26 | 2022-08-26 |
| DOMAIN | update.hannarng.kro.kr | 2022-08-26 | 2022-08-26 |
| DOMAIN | netra.atwebpages.com | 2022-08-26 | 2022-08-26 |
| DOMAIN | update.modernmap.n-e.kr | 2022-08-26 | 2022-08-26 |