I사 해킹사고 관련 악성코드 분석보고서
2016-07-28 • Hauri • Malicious code analysis report related to company I hacking incident •
http://www.hauri.co.kr/security/issue_view.html?intSeq=293&page=5&article_num=234
Hauri analyzed malware used in the Interpark breach, where a shopping mall employee's PC was compromised through an email attachment sent under the guise of an acquaintance. The sample attempted to hide infection by launching a legitimate screensaver file while copying itself into AppData paths such as Microsoft Office and Internet Explorer compatibility directories. Its persistence and execution flow used an /AUTOSTART argument, mutex creation, and a copied ielowutil.exe component under the user's AppData profile. The malware contained encrypted or embedded socket data for SSL-based command communication with 190.185.124.125:443, 220.132.191.110:443, and 202.137.244.198:443, although those servers were reportedly down during analysis. The report is useful for defenders because it documents the initial social-engineering vector, host artifacts, execution paths, and C2 endpoints associated with the intrusion.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 220.132.191.110 | 2016-07-28 | 2017-12-12 |
| IPv4 | 202.137.244.198 | 2016-07-28 | 2016-07-28 |
| IPv4 | 190.185.124.125 | 2016-07-28 | 2016-07-28 |