HIDDEN COBRA 악성코드(java.exe) 분석 보고서

2018-10-02 Igloo HIDDEN COBRA malware (java.exe) analysis report

https://www.igloo.co.kr/security-information/hidden-cobra-%ec%95%85%ec%84%b1%ec%bd%94%eb%93%9cjava-exe-%eb%b6%84%ec%84%9d-%eb%b3%b4%ea%b3%a0%ec%84%9c/

Igloo analyzes a collected HIDDEN COBRA java.exe malware sample that connects to hardcoded command-and-control servers and executes attacker commands when a connection succeeds. The sample is reported to be created by a 64-bit malicious DLL and stores required function names as encrypted strings that are decrypted at runtime. Static analysis shows host profiling for CPU, disk, and network adapter information, use of select() to support connections to multiple C2 servers, and command routines for registry modification, service removal, file search, file read/write, and process creation. The C2 servers were closed at analysis time, so the dynamic behavior could not be fully confirmed, but the code paths indicate remote command execution via cmd.exe and other host-management capabilities. The report provides a SHA-256 sample hash and links its findings to US-CERT reporting for HIDDEN COBRA defensive correlation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3c809a10106990ba93ec0ed3b63ec85… 2018-10-02 2018-10-02
HASH 6ab301fc3296e1ceb140bf5d294894c5 2018-10-02 2018-10-02
IPv4 184.107.209.2 2017-12-19 2018-10-02
IPv4 181.119.19.56 2017-12-19 2018-10-02
IPv4 80.91.118.45 2017-12-19 2018-10-02
IPv4 111.207.78.204 2017-12-19 2018-10-02

Related Actors

Related Reports

« Back