APT-C-28(ScarCruft)组织针对能源方向投放Rokrat后门活动分析
2023-07-13 • Qihoo360 • Analysis of APT-C-28 (ScarCruft) organization's Rokrat backdoor activities targeting the energy direction •
360’s threat research team reported APT-C-28/ScarCruft activity using an energy-sector lure about the Sharara-to-Mellitah oil pipeline to deliver the RokRAT backdoor. The attack used a large padded LNK file containing a decoy PDF and malicious BAT logic, then PowerShell pulled an encrypted RokRAT payload from OneDrive, decrypted it, and ran it in memory. The RokRAT sample collected host and user details, supported file transfer, command execution, screenshots, and keylogging, and used cloud storage APIs including pCloud, Yandex, and Dropbox for command and file exchange. The report notes continuity with earlier RokRAT behavior, including familiar file naming, code structure, and HTTP content-type patterns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4fe698c235d03a271305db8ffdaa9e36 | 2023-07-13 | 2023-07-13 |
| HASH | 4d3464b23dd4fb141c8fcc4cbf541832 | 2023-07-13 | 2023-07-13 |
| HASH | 2c180bf7a1e6dbe84060c3b5aa53feb7 | 2023-07-13 | 2023-07-13 |
| HASH | 7b7c43ed1eb6a423bdcfd0484fe560c3 | 2023-07-13 | 2023-07-13 |
| HASH | 85e71578ad7fea3c15095b6185b14881 | 2023-05-23 | 2023-07-13 |
| URL | https://1drv.ms/u/s!AjQNLvEE_CU… | 2023-05-01 | 2023-07-13 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-05-01 | 2023-07-13 |