APT37: Final1stspy Reaping the FreeMilk

2018-10-03 Intezer

https://www.intezer.com/apt37-final1stspy-reaping-the-freemilk/

Thumbnail for APT37: Final1stspy Reaping the FreeMilk

Intezer linked Final1stspy activity to APT37/Group123 by analyzing code reuse across NOKKI, KONNI, KimJongRAT, DOGCALL/ROKRAT, and FreeMilk-related samples. The reported NOKKI-associated malicious document used VBScript to download Final1stspy, whose `LoadDll` executable loaded a `hadowexecute` DLL before ultimately delivering DOGCALL/ROKRAT. Intezer found an earlier Final1stspy DLL through YARA hunting and identified a unique OS-information-gathering function shared with Group123's ROKRAT code. The report published SHA-256 indicators for Final1stspy DLL/EXE samples and related FreeMilk/ROKRAT samples.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2011b9aa61d280ca9397398434af94e… 2018-10-03 2020-03-09
HASH fb94a5e30de7afd1d9072ccedd90a24… 2018-10-01 2020-03-09
HASH ef40f7ddff404d1193e025081780e32… 2017-10-05 2020-03-09
HASH 26ad5f8889d10dc45dcf1d3c626416e… 2018-10-03 2018-10-03
HASH 65ec544841dbe666d20de0864951581… 2018-10-03 2018-10-03
HASH 01045aeea5198cbc893066d7e496f13… 2018-10-03 2018-10-03
HASH 0669c71740134323793429d10518576… 2018-10-01 2018-10-03
HASH 99c1b4887d96cb94f32b280c1039b3a… 2017-10-05 2018-10-03
HASH 7f35521cdbaa4e86143656ff9c52cef… 2017-10-05 2018-10-03

Related Actors

Related Reports

« Back