I사 인증서 유출 관련 악성코드

2016-02-23 Sands Lab Malicious code related to company I certificate leakage

http://story.malwares.com/75

A leaked digital certificate from a security vendor was abused to sign malware, exploiting trust in software used by financial institutions and public-sector organizations. The signed executable is described as a downloader that contacted an external server, issued a DBD command, and reported download success or failure back to that server, although downloads were no longer active at analysis time. The malware copied itself to a specific path with random data added to change its hash and evade antivirus detection, while internal strings such as the Run registry path and installation path were encoded. The excerpt provides the C&C address 165.194.123.67:8008 and several SHA-256 hashes for EXE and DLL samples, making it useful for validating code-signing abuse, persistence, and downloader activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 192.99.223.115 2016-02-23 2020-04-16
IPv4 165.194.123.67 2016-02-23 2020-04-16
HASH 5af3a8edf2d12312da2853b4a9d7436… 2016-02-23 2016-02-23
HASH 594fe5e2274a7944b461dae3919adb2… 2016-02-23 2016-02-23
HASH 59a0c59f192997c2c6741f1de3bb1ce… 2016-02-23 2016-02-23
HASH bbb0e5c004ec6a552ee5dca67fed0f9… 2016-02-23 2016-02-23
HASH e7322cfe8eb767b2a96a24e1de38184… 2016-02-23 2016-02-23

Related Reports

« Back