Andariel 그룹의 Apache ActiveMQ 취약점 (CVE-2023-46604) 공격 정황

2023-11-17 Ahnlab Andariel group's Apache ActiveMQ vulnerability (CVE-2023-46604) attack context

https://asec.ahnlab.com/ko/59130/

Thumbnail for Andariel 그룹의 Apache ActiveMQ 취약점 (CVE-2023-46604) 공격 정황

ASEC assessed that Andariel may have abused the Apache ActiveMQ remote code execution flaw CVE-2023-46604 to install NukeSped and TigerRat backdoors on exposed servers. The evidence is circumstantial: the affected system was repeatedly hit after public disclosure of the flaw, showed HelloKitty and downloader activity seen in other ActiveMQ exploitation, and later contained Andariel linked NukeSped. The NukeSped variant supports file download, command execution with result return, and process termination, with encrypted strings and HTTP headers used for C2 commands. The report also links a payload URL at 27.102.128[.]152:8098 to TigerRat activity and lists additional Cobalt Strike, Meterpreter, downloader, and ransomware artifacts seen around the vulnerable server.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c2f8c9bb7df688d0a7030a96314bb493 2023-11-10 2024-07-25
HASH 7699ba4eab5837a4ad9d5d6bbedffc18 2023-11-17 2023-11-27
HASH 11ec319e9984a71d80df1302fe77332d 2023-11-17 2023-11-27
HASH c55eb07ef4c07e5ba63f7f0797dfd536 2023-11-17 2023-11-27
HASH 31cbc75319ea60f45eb114c2faad21f9 2023-11-17 2023-11-27
HASH 478dcb54e0a610a160a079656b9582de 2023-11-17 2023-11-27
HASH dc9d60ce5b3d071942be126ed733bfb8 2023-11-17 2023-11-27
HASH beb219abe2ba5e9fd7d51a178ac2caca 2023-11-17 2023-11-27
HASH 26ff72b0b85e764400724e442c164046 2023-11-17 2023-11-27
HASH 4eead95202e6a0e4936f681fd5579582 2023-11-17 2023-11-27
HASH 160f7d2307bbc0e8a1b6ac03b8715e4f 2023-11-17 2023-11-27
IPv4 206.166.251.186 2023-11-17 2023-11-27
IPv4 137.175.17.172 2023-11-17 2023-11-27
IPv4 27.102.114.215 2023-11-17 2023-11-27
IPv4 137.175.17.221 2023-11-17 2023-11-27
IPv4 168.100.9.154 2023-11-17 2023-11-27
IPv4 176.105.255.60 2023-11-17 2023-11-27
IPv4 27.102.128.152 2023-11-10 2023-11-27

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back