Inside TDrop2: Technical Analysis of new Dark Seoul Malware

2015-11-23 Paloalto Networks

https://researchcenter.paloaltonetworks.com/2015/11/inside-tdrop2-technical-analysis-of-new-dark-seoul-malware/

Thumbnail for Inside TDrop2: Technical Analysis of new Dark Seoul Malware

Unit 42 analyzes TDrop2 malware used in a campaign tied to Dark Seoul and Operation Troy activity, targeting European transportation organizations through a trojanized security-camera video player package. The first-stage installer drops both the legitimate video player and malicious executables, performs parent-process checks, dynamically loads APIs, and uses process hollowing to run inside legitimate Windows binaries. A downloader retrieves a disguised executable from a .jpg URL, repairs its altered PE header from "DW" to "MZ", and launches later stages that add Run-key persistence, collect victim information, and poll C2 servers. The final payload supports command execution, download-and-execute functions, encrypted and custom-base64-encoded C2 traffic, and reconnaissance commands such as system, network, process, Outlook, temp, and Microsoft Office directory listings.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 49a665d51e0f17c6554f11be7abcdcc… 2015-11-23 2015-11-23
HASH c89a97b99063a74eeea8b7288196cb96 2015-11-23 2015-11-23
HASH 01635c842f4cee4e5a97fba2341207b… 2015-11-23 2015-11-23
HASH f6f3d7264f7478b472894b90a66ea2a2 2015-11-23 2015-11-23
HASH 285352cad75dc32baae10abf68005397 2015-11-23 2015-11-23
HASH 1b86a66a0a0d6a619d8f2cd1e2904ef… 2015-11-23 2015-11-23
HASH 29289c19c414cf79e61e095c1500938a 2015-11-23 2015-11-23
HASH 23637a57ea2f984afaf991d4e90e3f4a 2015-11-23 2015-11-23
HASH 6270129b7ee49aef969e8c18fad584e… 2015-11-23 2015-11-23
HASH 6c53a43acfb8f3a1c7b37eb614cbd89… 2015-11-23 2015-11-23
HASH 7315e7fd14518b8a27750d5f717a9fa… 2015-11-23 2015-11-23
HASH 8bb8e4193ed7a115b97046afaa6cf37… 2015-11-23 2015-11-23
HASH ee878a8adee367371242d624f79531f… 2015-11-23 2015-11-23
HASH 0ef3ec648b63badadb6ba947e4f90f1… 2015-11-23 2015-11-23
HASH a10cf8b278af1bbc93e03e299082021… 2015-11-23 2015-11-23
HASH 25d283bea4136f07c13ff3902821a20… 2015-11-23 2015-11-23
HASH 56c9bb7a7f3af5f55f4e4fa94e8c6acc 2015-11-23 2015-11-23
HASH 2356db510c8c2d5f72945d3d0b9b826… 2015-11-23 2015-11-23
HASH 3e9bfa7f4efd3b5687872feae62138f… 2015-11-23 2015-11-23
HASH b67638c91eae7db255e41f7cc0cce46b 2015-11-23 2015-11-23
HASH e64443e3f3d86d0ab86daeb0b9e51d2… 2015-11-23 2015-11-23
URL http://mcm-yachtmanagement.com/… 2015-11-23 2015-11-23
URL http://www.junfac.com/tires/ski… 2015-11-23 2015-11-23
URL http://www.combra.eu/includes/i… 2015-11-23 2015-11-23
HASH 43eb1b6bf1707e55a39e87985eda455… 2015-11-18 2015-11-23
HASH a02e1cb1efbe8f3551cc3a4b452c2b7… 2015-11-18 2015-11-23
DOMAIN mcm-yachtmanagement.com 2015-11-18 2015-11-23

Related Reports

« Back