HIDDEN COBRA 악성코드 분석 보고서

2018-08-03 Igloo HIDDEN COBRA Malware Analysis Report

https://www.igloo.co.kr/security-information/hidden-cobra-%ec%95%85%ec%84%b1%ec%bd%94%eb%93%9c-%eb%b6%84%ec%84%9d-%eb%b3%b4%ea%b3%a0%ec%84%9c/

Igloo analyzes HIDDEN COBRA malware built around a dropper that installs Joanap, a remote access backdoor, and Brambul, an SMB-based worm component. After checking for the SCardPrv service to determine whether a host is already infected, the dropper creates scardprv.dll, Wmmvsvc.dll, and mssscardprv.ax from embedded resources and registers the DLLs as services. scardprv.dll runs as a TCP/443 backdoor and can search for and delete specific directories, while Wmmvsvc.dll reads IP and port data from mssscardprv.ax to attempt SMB connections and propagate to remote systems. The worm attempts Administrator logins, configures ADMIN$ paths based on Windows version, copies Wmmvsvc.dll and mssscardprv.ax to remote hosts, and registers the copied DLL as a service for secondary infection. The malware also connects to Google mail servers and sends infected-system information to a hardcoded address, with hashes and US-CERT references supplied for validation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 077d9e0e12357d27f7f0c336239e961… 2018-08-03 2020-03-09
HASH a1c483b0ee740291b91b11e18dd05f0… 2015-10-26 2020-03-09
HASH ea46ed5aed900cd9f01156a1cd446cb… 2018-08-03 2018-08-03

Related Actors

Related Reports

« Back