HIDDEN COBRA 악성코드 분석 보고서
2018-08-03 • Igloo • HIDDEN COBRA Malware Analysis Report •
Igloo analyzes HIDDEN COBRA malware built around a dropper that installs Joanap, a remote access backdoor, and Brambul, an SMB-based worm component. After checking for the SCardPrv service to determine whether a host is already infected, the dropper creates scardprv.dll, Wmmvsvc.dll, and mssscardprv.ax from embedded resources and registers the DLLs as services. scardprv.dll runs as a TCP/443 backdoor and can search for and delete specific directories, while Wmmvsvc.dll reads IP and port data from mssscardprv.ax to attempt SMB connections and propagate to remote systems. The worm attempts Administrator logins, configures ADMIN$ paths based on Windows version, copies Wmmvsvc.dll and mssscardprv.ax to remote hosts, and registers the copied DLL as a service for secondary infection. The malware also connects to Google mail servers and sends infected-system information to a hardcoded address, with hashes and US-CERT references supplied for validation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 077d9e0e12357d27f7f0c336239e961… | 2018-08-03 | 2020-03-09 |
| HASH | a1c483b0ee740291b91b11e18dd05f0… | 2015-10-26 | 2020-03-09 |
| HASH | ea46ed5aed900cd9f01156a1cd446cb… | 2018-08-03 | 2018-08-03 |