APT43 배후의 다단계 드롭박스 명령과 TutorialRAT
2024-04-17 • Genians • APT43 behind multi-stage Dropbox commands and TutorialRAT •
APT43 is reported using a multi-stage attack chain that abuses Dropbox cloud storage and deploys TutorialRAT as part of activity linked to the BabyShark campaign lineage. The source highlights lures impersonating policy meetings, advisory sessions, surveys, and lecture notices, with an initial approach through normal email followed by responsive spear-phishing tactics. Use of a legitimate cloud service as attack infrastructure can reduce visibility for defenders who monitor only obviously malicious hosting, while the RAT stage creates endpoint detection opportunities. Security teams should review the archive for email lure patterns, Dropbox-based staging, TutorialRAT behavior, and telemetry that can separate legitimate cloud use from adversary operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b9898e8e5b6494bcc219462c6be7c248 | 2024-04-17 | 2024-06-12 |
| HASH | d19253d84c6cb8fb6064e6d33bed556f | 2024-04-17 | 2024-06-12 |
| HASH | 0040f03faf5bbdc555f2039a4e33a82b | 2024-01-30 | 2024-06-12 |
| HASH | 61a30992e0a7ab93cd3a47cc51284b35 | 2024-04-17 | 2024-04-17 |
| HASH | f395012ff30a846d0e7ed787147f5723 | 2024-04-17 | 2024-04-17 |
| HASH | 544963f602ec6c97994d38ce39368d79 | 2024-04-17 | 2024-04-17 |
| HASH | ade1d12604dd9d62f6ef97a93cda142b | 2024-04-17 | 2024-04-17 |
| HASH | 781acd3a8250da862e48425d078b54ad | 2024-04-17 | 2024-04-17 |
| HASH | 2f9125a538d84dd952f72722f28575b8 | 2024-04-17 | 2024-04-17 |
| HASH | 5ad5ace1ec82538f66acf13e48cf8db4 | 2024-04-17 | 2024-04-17 |
| HASH | 515194ef77fbbe04845de290eefd0049 | 2024-04-17 | 2024-04-17 |
| HASH | a9276bae977589f3f670f26b2cb8a9f1 | 2024-04-17 | 2024-04-17 |
| DOMAIN | meatalk.com | 2024-04-17 | 2024-04-17 |
| DOMAIN | iso3488.co.kr | 2024-04-17 | 2024-04-17 |
| DOMAIN | strehab.com | 2024-04-17 | 2024-04-17 |
| DOMAIN | kyungdaek.com | 2024-04-17 | 2024-04-17 |
| DOMAIN | siloamclinic.com | 2024-04-17 | 2024-04-17 |
| DOMAIN | aymdtt.co.kr | 2024-04-17 | 2024-04-17 |
| DOMAIN | vwellpain.com | 2024-04-17 | 2024-04-17 |
| IPv4 | 183.111.141.93 | 2024-04-17 | 2024-04-17 |
| HASH | a4bd6d00abbd79ab00161ff538cfe703 | 2024-04-03 | 2024-04-17 |
| HASH | eb08ab3854168c834ab154facfe695a3 | 2024-03-22 | 2024-04-17 |
| HASH | 1e66ac680d0edfe18d97b89e46c7e82e | 2024-03-22 | 2024-04-17 |
| HASH | c700195f61635b9a6fb1ee4359b91940 | 2024-03-22 | 2024-04-17 |
| DOMAIN | regard.co.kr | 2024-03-18 | 2024-04-17 |
| HASH | 3e3013fe03f7416b8d1e96591f8e5839 | 2024-01-30 | 2024-04-17 |
| HASH | fcdcc6c56ae43f7a78413cc5204e9314 | 2024-01-30 | 2024-04-17 |
| HASH | 32519b46b55792084240f850e0c94298 | 2024-01-30 | 2024-04-17 |
| DOMAIN | gbionet.com | 2024-01-30 | 2024-04-17 |
| IPv4 | 122.155.191.33 | 2024-01-30 | 2024-04-17 |
| HASH | dce864eabfbd6445682a4671a2fee1a9 | 2023-12-29 | 2024-04-17 |
| DOMAIN | dddon.kr | 2023-12-29 | 2024-04-17 |
| HASH | 64dee04b6e6404c14d10971adf35c3a7 | 2023-11-09 | 2024-04-17 |
| HASH | eb614c99614c3365bdc926a73ef7a492 | 2023-11-09 | 2024-04-17 |
| HASH | fb5aec165279015f17b29f9f2c730976 | 2023-11-09 | 2024-04-17 |
| HASH | b70bc31b537caf411f97a991d8292c5a | 2023-11-09 | 2024-04-17 |
| IPv4 | 165.154.230.24 | 2023-11-09 | 2024-04-17 |
| IPv4 | 218.150.78.197 | 2023-09-26 | 2024-04-17 |
| HASH | 8133c5f663f89b01b30a052749b5a988 | 2023-06-16 | 2024-04-17 |
| DOMAIN | well-story.co.kr | 2023-06-16 | 2024-04-17 |