KISA-Security-Upgrade 파일로 위장한 악성코드

2023-07-28 Hauri Malicious code disguised as KISA-Security-Upgrade file

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=52

Attachments

2023-07-17_ìì_ëì_ë³ê³ìKISA-Security-Upgrade_íì¼ë_ììí_ììì½ë.pdf (2 MB)

Hauri analyzed malware disguised as a KISA-Security-Upgrade executable that unpacked embedded archives and dropped additional malicious files. The initial executable posed as a Korean security-upgrade file to induce user execution, wrote data under a temporary directory, and launched a dropped file through CreateProcessW with installer-style arguments. The next-stage component displayed a fake normal installer window while extracting a malicious archive and decompression utility to create and execute additional malware, illustrating the risk of unverified update packages.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c447624d99292f1465b51d3efeda9e73 2023-07-28 2023-08-16
HASH 97de7d4c5115c02d08de760e1dafc403 2023-07-28 2023-08-16
HASH c5e0a2b881a60fb3440bb78e9920dccd 2023-06-09 2023-08-16
DOMAIN pita1.sportsontheweb.net 2023-06-09 2023-08-16
HASH 607e97d2264314fd2e626ca48dd580e8 2023-07-28 2023-07-28
URL http://pita1.sportsontheweb.net 2023-07-28 2023-07-28

Related Reports

« Back