3CX DesktopApp 공급망 공격, 국내에서도 확인
2023-04-05 • Ahnlab • 3CX DesktopApp supply chain attack confirmed in Korea •
AhnLab describes the 3CX DesktopApp supply-chain compromise reported by CrowdStrike as activity by a North Korea-based actor and shows that Korean victims installed affected Windows versions before public disclosure, including logs from a domestic university. The malicious Windows installer loaded a trojanized ffmpeg.dll, decrypted data appended to d3dcompiler_47.dll, and ran downloader shellcode that fetched icon files from a GitHub repository before decoding C2 URLs used to retrieve additional malware, reportedly including an infostealer. The report also covers macOS DMG samples whose libffmpeg.dylib stored XOR-encoded C2 addresses. Representative infrastructure included raw.githubusercontent.com/IconStorages/images and domains such as msstorageazure.com, officestoragebox.com, and visualstudiofactory.com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a64fa9f1c76457ecc58402142a8728c… | 2023-03-30 | 2024-12-27 |
| HASH | 5009c7d1590c1f8c05827122172583d… | 2023-03-30 | 2024-12-27 |
| HASH | fee4f9dabc094df24d83ec1a8c4e4ff… | 2023-03-30 | 2024-12-27 |
| HASH | 87c5d0c93b80acf61d24e7aaf0faae2… | 2023-03-30 | 2024-12-27 |
| HASH | e6bbc33815b9f20b0cf832d7401dd89… | 2023-03-29 | 2024-12-27 |
| DOMAIN | visualstudiofactory.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageazure.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | zacharryblogs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | sourceslabs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| HASH | aa4e398b3bd8645016d8090ffc77d15… | 2023-03-30 | 2023-05-02 |
| HASH | c485674ee63ec8d4e8fde9800788175… | 2023-03-30 | 2023-04-28 |
| HASH | 8ab3a5eaaf8c296080fadf56b265194… | 2023-03-30 | 2023-04-28 |
| HASH | 7986bbaee8940da11ce089383521ab4… | 2023-03-30 | 2023-04-28 |
| HASH | 11be1803e2e307b647a8a7e02d12833… | 2023-03-30 | 2023-04-28 |
| HASH | 5407cda7d3a75e7b1e030b1f33337a5… | 2023-03-29 | 2023-04-28 |
| HASH | 59e1edf4d82fae4978e97512b0331b7… | 2023-03-29 | 2023-04-28 |
| HASH | aa124a4b4df12b34e74ee7f6c683b2e… | 2023-03-29 | 2023-04-28 |
| URL | https://azureonlinestorage.com/… | 2023-03-30 | 2023-04-05 |
| URL | https://akamaitechcloudservices… | 2023-03-30 | 2023-04-05 |
| URL | https://pbxsources.com/exchange | 2023-03-30 | 2023-04-05 |
| URL | https://zacharryblogs.com/feed | 2023-03-30 | 2023-04-05 |
| URL | https://msstorageboxes.com/offi… | 2023-03-30 | 2023-04-05 |
| URL | https://msedgepackageinfo.com/m… | 2023-03-30 | 2023-04-05 |
| URL | https://azuredeploystore.com/cl… | 2023-03-30 | 2023-04-05 |
| URL | https://glcloudservice.com/v1/c… | 2023-03-30 | 2023-04-05 |
| URL | https://visualstudiofactory.com… | 2023-03-30 | 2023-04-05 |
| URL | https://officeaddons.com/techno… | 2023-03-30 | 2023-04-05 |
| URL | https://pbxcloudeservices.com/p… | 2023-03-30 | 2023-04-05 |
| URL | https://sourceslabs.com/downloa… | 2023-03-30 | 2023-04-05 |
| URL | https://msstorageazure.com/wind… | 2023-03-30 | 2023-04-05 |
| URL | https://officestoragebox.com/ap… | 2023-03-30 | 2023-04-05 |