I사 해킹사고 관련 악성코드 분석보고서

2016-07-28 Hauri Malicious code analysis report related to company I hacking incident

http://www.hauri.co.kr/security/issue_view.html?intSeq=293&page=5&article_num=234

Thumbnail for I사 해킹사고 관련 악성코드 분석보고서

Hauri analyzed malware used in the Interpark breach, where a shopping mall employee's PC was compromised through an email attachment sent under the guise of an acquaintance. The sample attempted to hide infection by launching a legitimate screensaver file while copying itself into AppData paths such as Microsoft Office and Internet Explorer compatibility directories. Its persistence and execution flow used an /AUTOSTART argument, mutex creation, and a copied ielowutil.exe component under the user's AppData profile. The malware contained encrypted or embedded socket data for SSL-based command communication with 190.185.124.125:443, 220.132.191.110:443, and 202.137.244.198:443, although those servers were reportedly down during analysis. The report is useful for defenders because it documents the initial social-engineering vector, host artifacts, execution paths, and C2 endpoints associated with the intrusion.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 220.132.191.110 2016-07-28 2017-12-12
IPv4 202.137.244.198 2016-07-28 2016-07-28
IPv4 190.185.124.125 2016-07-28 2016-07-28

Related Reports

« Back