I사 인증서 유출 관련 악성코드
2016-02-23 • Sands Lab • Malicious code related to company I certificate leakage •
A leaked digital certificate from a security vendor was abused to sign malware, exploiting trust in software used by financial institutions and public-sector organizations. The signed executable is described as a downloader that contacted an external server, issued a DBD command, and reported download success or failure back to that server, although downloads were no longer active at analysis time. The malware copied itself to a specific path with random data added to change its hash and evade antivirus detection, while internal strings such as the Run registry path and installation path were encoded. The excerpt provides the C&C address 165.194.123.67:8008 and several SHA-256 hashes for EXE and DLL samples, making it useful for validating code-signing abuse, persistence, and downloader activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 192.99.223.115 | 2016-02-23 | 2020-04-16 |
| IPv4 | 165.194.123.67 | 2016-02-23 | 2020-04-16 |
| HASH | 5af3a8edf2d12312da2853b4a9d7436… | 2016-02-23 | 2016-02-23 |
| HASH | 594fe5e2274a7944b461dae3919adb2… | 2016-02-23 | 2016-02-23 |
| HASH | 59a0c59f192997c2c6741f1de3bb1ce… | 2016-02-23 | 2016-02-23 |
| HASH | bbb0e5c004ec6a552ee5dca67fed0f9… | 2016-02-23 | 2016-02-23 |
| HASH | e7322cfe8eb767b2a96a24e1de38184… | 2016-02-23 | 2016-02-23 |