A Deep Dive Analysis of the FALLCHILL Remote Administration Tool
2017-11-28 • Fortinet •
Fortinet analyzed FALLCHILL, a remote administration tool linked in the excerpt to HIDDEN COBRA through overlapping command-and-control infrastructure and a Korean locale artifact. The malware exists in 32-bit and 64-bit variants, decrypts Windows API names dynamically to hinder static analysis, and uses C2 addresses including 125.212.132.222 and 175.100.189.174, with 10.10.30.110 likely left from author testing. After connecting to its C2, FALLCHILL starts a shell-like command loop that can retrieve and launch additional payloads, create processes as another user, manipulate timestamps, enumerate disks, change directories, and remove itself. The analysis matters because validated IOCs, malware hashes, and detection names such as FALLCHILL.Botnet help defenders identify and respond to a North Korea-linked RAT used for remote control of compromised systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a606716355035d4a1ea0b15f3bee30a… | 2017-11-20 | 2020-03-09 |
| IPv4 | 175.100.189.174 | 2017-11-20 | 2018-04-07 |
| HASH | 0a118eb23399000d148186b9079fa59… | 2017-11-28 | 2017-11-28 |
| IPv4 | 125.212.132.222 | 2017-11-28 | 2017-11-28 |