후쿠시마 오염수 방류 내용을 이용한 CHM 악성코드 : RedEyes(ScarCruft)
2023-09-04 • Ahnlab • CHM malware using Fukushima contaminated water discharge: RedEyes (ScarCruft) •
AhnLab reported renewed distribution of CHM malware believed to be associated with RedEyes/ScarCruft, using public concern over Fukushima contaminated-water discharge as the lure. Unlike earlier variants that launched mshta directly from the CHM help file, this sample registered a Run key command so the mshta chain would execute after reboot. The decoded PowerShell acted as a backdoor that contacted navercorp[.]ru paths for command retrieval and Base64-encoded result reporting. Documented commands covered file inventory and upload, directory compression and exfiltration, file download, scheduled-task registration, archive extraction, and file renaming, enabling follow-on payload delivery and information theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 52f71fadf0ea5ffacd753e83a3d0af1a | 2023-09-04 | 2023-09-08 |
| URL | http://navercorp.ru/dashboard/i… | 2023-09-04 | 2023-09-08 |
| URL | http://navercorp.ru/dashboard/i… | 2023-09-04 | 2023-09-08 |
| DOMAIN | navercorp.ru | 2023-09-04 | 2023-09-08 |