APT37: Final1stspy Reaping the FreeMilk
2018-10-03 • Intezer •
https://www.intezer.com/apt37-final1stspy-reaping-the-freemilk/
Intezer linked Final1stspy activity to APT37/Group123 by analyzing code reuse across NOKKI, KONNI, KimJongRAT, DOGCALL/ROKRAT, and FreeMilk-related samples. The reported NOKKI-associated malicious document used VBScript to download Final1stspy, whose `LoadDll` executable loaded a `hadowexecute` DLL before ultimately delivering DOGCALL/ROKRAT. Intezer found an earlier Final1stspy DLL through YARA hunting and identified a unique OS-information-gathering function shared with Group123's ROKRAT code. The report published SHA-256 indicators for Final1stspy DLL/EXE samples and related FreeMilk/ROKRAT samples.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2011b9aa61d280ca9397398434af94e… | 2018-10-03 | 2020-03-09 |
| HASH | fb94a5e30de7afd1d9072ccedd90a24… | 2018-10-01 | 2020-03-09 |
| HASH | ef40f7ddff404d1193e025081780e32… | 2017-10-05 | 2020-03-09 |
| HASH | 26ad5f8889d10dc45dcf1d3c626416e… | 2018-10-03 | 2018-10-03 |
| HASH | 65ec544841dbe666d20de0864951581… | 2018-10-03 | 2018-10-03 |
| HASH | 01045aeea5198cbc893066d7e496f13… | 2018-10-03 | 2018-10-03 |
| HASH | 0669c71740134323793429d10518576… | 2018-10-01 | 2018-10-03 |
| HASH | 99c1b4887d96cb94f32b280c1039b3a… | 2017-10-05 | 2018-10-03 |
| HASH | 7f35521cdbaa4e86143656ff9c52cef… | 2017-10-05 | 2018-10-03 |