KISA-Security-Upgrade 파일로 위장한 악성코드
2023-07-28 • Hauri • Malicious code disguised as KISA-Security-Upgrade file •
https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=52
Attachments
Hauri analyzed malware disguised as a KISA-Security-Upgrade executable that unpacked embedded archives and dropped additional malicious files. The initial executable posed as a Korean security-upgrade file to induce user execution, wrote data under a temporary directory, and launched a dropped file through CreateProcessW with installer-style arguments. The next-stage component displayed a fake normal installer window while extracting a malicious archive and decompression utility to create and execute additional malware, illustrating the risk of unverified update packages.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c447624d99292f1465b51d3efeda9e73 | 2023-07-28 | 2023-08-16 |
| HASH | 97de7d4c5115c02d08de760e1dafc403 | 2023-07-28 | 2023-08-16 |
| HASH | c5e0a2b881a60fb3440bb78e9920dccd | 2023-06-09 | 2023-08-16 |
| DOMAIN | pita1.sportsontheweb.net | 2023-06-09 | 2023-08-16 |
| HASH | 607e97d2264314fd2e626ca48dd580e8 | 2023-07-28 | 2023-07-28 |
| URL | http://pita1.sportsontheweb.net | 2023-07-28 | 2023-07-28 |