A Deep Dive Analysis of the FALLCHILL Remote Administration Tool

2017-11-28 Fortinet

https://www.fortinet.com/blog/threat-research/a-deep-dive-analysis-of-the-fallchill-remote-administration-tool

Thumbnail for A Deep Dive Analysis of the FALLCHILL Remote Administration Tool

Fortinet analyzed FALLCHILL, a remote administration tool linked in the excerpt to HIDDEN COBRA through overlapping command-and-control infrastructure and a Korean locale artifact. The malware exists in 32-bit and 64-bit variants, decrypts Windows API names dynamically to hinder static analysis, and uses C2 addresses including 125.212.132.222 and 175.100.189.174, with 10.10.30.110 likely left from author testing. After connecting to its C2, FALLCHILL starts a shell-like command loop that can retrieve and launch additional payloads, create processes as another user, manipulate timestamps, enumerate disks, change directories, and remove itself. The analysis matters because validated IOCs, malware hashes, and detection names such as FALLCHILL.Botnet help defenders identify and respond to a North Korea-linked RAT used for remote control of compromised systems.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a606716355035d4a1ea0b15f3bee30a… 2017-11-20 2020-03-09
IPv4 175.100.189.174 2017-11-20 2018-04-07
HASH 0a118eb23399000d148186b9079fa59… 2017-11-28 2017-11-28
IPv4 125.212.132.222 2017-11-28 2017-11-28

Related Actors

Related Reports

« Back