Bisonal Malware Used in Attacks Against Russia and South Korea

2018-07-31 Paloalto Networks

https://researchcenter.paloaltonetworks.com/2018/07/unit42-bisonal-malware-used-attacks-russia-south-korea/

Thumbnail for Bisonal Malware Used in Attacks Against Russia and South Korea

Unit 42 identified a Bisonal campaign that targeted at least one Russian defense-related communications security company and one unidentified South Korean organization in early May 2018. The attackers used spear-phishing with a Windows executable disguised as a PDF and displayed a Rostec housing-project decoy to make the lure credible to the Russian victim. The dropper decrypted an embedded Bisonal DLL and decoy file with the RC4 key "34123412," wrote them under Windows Temp, and configured Run-key persistence through rundll32. The excerpt also notes common Bisonal tradecraft—government, military, and defense targets in South Korea, Russia, and Japan; occasional DDNS C2; target or campaign codes; and decoy documents—making the campaign useful for hunting related Bisonal activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0641fe04713fbdad272a6f8e9b44631… 2018-07-31 2018-07-31
HASH f431e0bed6b4b7ffef5e40b1b4b7078… 2018-07-31 2018-07-31
HASH b1da7e1963dc09c325ba3ea2442a54a… 2018-07-31 2018-07-31
HASH 359835c4a9dbe2d95e4834646597444… 2018-07-31 2018-07-31
HASH b2b764597d097fcb93c5b11cbd864ab… 2018-07-31 2018-07-31
HASH dfa1ad6083aa06b82edfa672925bb78… 2018-07-31 2018-07-31
HASH 43459f5117bee7b49f2cee7ce934471… 2018-07-31 2018-07-31
HASH 1128d10347dd602ecd3228faa389add… 2018-07-31 2018-07-31
DOMAIN kted56erhg.dynssl.com 2018-07-31 2018-07-31
DOMAIN games.my-homeip.com 2018-07-31 2018-07-31
DOMAIN euiro8966.organiccrap.com 2018-07-31 2018-07-31
IPv4 196.44.49.154 2018-07-31 2018-07-31
IPv4 116.193.155.38 2018-07-31 2018-07-31
« Back