3CX DesktopApp 공급망 공격, 국내에서도 확인

2023-04-05 Ahnlab 3CX DesktopApp supply chain attack confirmed in Korea

https://asec.ahnlab.com/ko/50965/

Thumbnail for 3CX DesktopApp 공급망 공격, 국내에서도 확인

AhnLab describes the 3CX DesktopApp supply-chain compromise reported by CrowdStrike as activity by a North Korea-based actor and shows that Korean victims installed affected Windows versions before public disclosure, including logs from a domestic university. The malicious Windows installer loaded a trojanized ffmpeg.dll, decrypted data appended to d3dcompiler_47.dll, and ran downloader shellcode that fetched icon files from a GitHub repository before decoding C2 URLs used to retrieve additional malware, reportedly including an infostealer. The report also covers macOS DMG samples whose libffmpeg.dylib stored XOR-encoded C2 addresses. Representative infrastructure included raw.githubusercontent.com/IconStorages/images and domains such as msstorageazure.com, officestoragebox.com, and visualstudiofactory.com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a64fa9f1c76457ecc58402142a8728c… 2023-03-30 2024-12-27
HASH 5009c7d1590c1f8c05827122172583d… 2023-03-30 2024-12-27
HASH fee4f9dabc094df24d83ec1a8c4e4ff… 2023-03-30 2024-12-27
HASH 87c5d0c93b80acf61d24e7aaf0faae2… 2023-03-30 2024-12-27
HASH e6bbc33815b9f20b0cf832d7401dd89… 2023-03-29 2024-12-27
DOMAIN visualstudiofactory.com 2023-03-29 2024-09-09
DOMAIN akamaitechcloudservices.com 2023-03-29 2024-09-09
DOMAIN msedgepackageinfo.com 2023-03-29 2024-09-09
DOMAIN msstorageazure.com 2023-03-29 2024-09-09
DOMAIN azureonlinestorage.com 2023-03-29 2024-09-09
DOMAIN zacharryblogs.com 2023-03-29 2024-09-09
DOMAIN officestoragebox.com 2023-03-29 2024-09-09
DOMAIN pbxphonenetwork.com 2023-03-29 2024-09-09
DOMAIN sourceslabs.com 2023-03-29 2024-09-09
DOMAIN officeaddons.com 2023-03-29 2024-09-09
DOMAIN glcloudservice.com 2023-03-29 2024-09-09
DOMAIN pbxcloudeservices.com 2023-03-29 2024-09-09
DOMAIN azuredeploystore.com 2023-03-29 2024-09-09
DOMAIN pbxsources.com 2023-03-29 2024-09-09
DOMAIN msstorageboxes.com 2023-03-29 2024-09-09
HASH aa4e398b3bd8645016d8090ffc77d15… 2023-03-30 2023-05-02
HASH c485674ee63ec8d4e8fde9800788175… 2023-03-30 2023-04-28
HASH 8ab3a5eaaf8c296080fadf56b265194… 2023-03-30 2023-04-28
HASH 7986bbaee8940da11ce089383521ab4… 2023-03-30 2023-04-28
HASH 11be1803e2e307b647a8a7e02d12833… 2023-03-30 2023-04-28
HASH 5407cda7d3a75e7b1e030b1f33337a5… 2023-03-29 2023-04-28
HASH 59e1edf4d82fae4978e97512b0331b7… 2023-03-29 2023-04-28
HASH aa124a4b4df12b34e74ee7f6c683b2e… 2023-03-29 2023-04-28
URL https://azureonlinestorage.com/… 2023-03-30 2023-04-05
URL https://akamaitechcloudservices… 2023-03-30 2023-04-05
URL https://pbxsources.com/exchange 2023-03-30 2023-04-05
URL https://zacharryblogs.com/feed 2023-03-30 2023-04-05
URL https://msstorageboxes.com/offi… 2023-03-30 2023-04-05
URL https://msedgepackageinfo.com/m… 2023-03-30 2023-04-05
URL https://azuredeploystore.com/cl… 2023-03-30 2023-04-05
URL https://glcloudservice.com/v1/c… 2023-03-30 2023-04-05
URL https://visualstudiofactory.com… 2023-03-30 2023-04-05
URL https://officeaddons.com/techno… 2023-03-30 2023-04-05
URL https://pbxcloudeservices.com/p… 2023-03-30 2023-04-05
URL https://sourceslabs.com/downloa… 2023-03-30 2023-04-05
URL https://msstorageazure.com/wind… 2023-03-30 2023-04-05
URL https://officestoragebox.com/ap… 2023-03-30 2023-04-05

Related Reports

« Back