HIDDEN COBRA 악성코드(java.exe) 분석 보고서
2018-10-02 • Igloo • HIDDEN COBRA malware (java.exe) analysis report •
Igloo analyzes a collected HIDDEN COBRA java.exe malware sample that connects to hardcoded command-and-control servers and executes attacker commands when a connection succeeds. The sample is reported to be created by a 64-bit malicious DLL and stores required function names as encrypted strings that are decrypted at runtime. Static analysis shows host profiling for CPU, disk, and network adapter information, use of select() to support connections to multiple C2 servers, and command routines for registry modification, service removal, file search, file read/write, and process creation. The C2 servers were closed at analysis time, so the dynamic behavior could not be fully confirmed, but the code paths indicate remote command execution via cmd.exe and other host-management capabilities. The report provides a SHA-256 sample hash and links its findings to US-CERT reporting for HIDDEN COBRA defensive correlation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3c809a10106990ba93ec0ed3b63ec85… | 2018-10-02 | 2018-10-02 |
| HASH | 6ab301fc3296e1ceb140bf5d294894c5 | 2018-10-02 | 2018-10-02 |
| IPv4 | 184.107.209.2 | 2017-12-19 | 2018-10-02 |
| IPv4 | 181.119.19.56 | 2017-12-19 | 2018-10-02 |
| IPv4 | 80.91.118.45 | 2017-12-19 | 2018-10-02 |
| IPv4 | 111.207.78.204 | 2017-12-19 | 2018-10-02 |