APT37 공격 그룹의 지속적 위협 공격
2025-03-20 • Hauri • ( Document No : DT-20250320-001 ) •
https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=74
Attachments
APT37 activity is described using malicious LNK files disguised as Microsoft Store update content to trigger infection. When executed, the LNK drops a decoy document and batch file, changes the shortcut into an HTML file, and uses obfuscated code to retrieve a CAB payload from a compromised legitimate South Korean company website. The infection chain registers MicrosoftAppStoreAutoUpdateTaskMachine as a scheduled task, runs MicrosoftAppStore.exe with appstore.version, and attempts to download an additional MicroAppStoreTemp28h2.bat payload from the same abused infrastructure. The decoy themes include aviation, banking, and security, showing socially targeted lures across sensitive sectors, with hashes and C2 paths supplied for detection and response.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 90026c2dbdb294b13fd03da2be011dd1 | 2025-03-20 | 2025-09-14 |
| HASH | dea8785b4c54d9ae6fa9c24de77531eb | 2025-03-20 | 2025-03-20 |
| HASH | de26582dda75c138f35e932dd2424eea | 2025-03-20 | 2025-03-20 |
| HASH | 345decffc710344a55fe121df7692df8 | 2025-03-20 | 2025-03-20 |
| HASH | f51f60834ba1734ae3765661d0f2654a | 2025-03-20 | 2025-03-20 |
| HASH | bdde4878f82dda79d983464153d71009 | 2025-03-20 | 2025-03-20 |
| HASH | 640c6f987b24f35bb29d3db0f4b8c87b | 2025-03-20 | 2025-03-20 |
| HASH | 8a0d6260ecdf551342633c93c03e4511 | 2025-03-20 | 2025-03-20 |