Meterpreter를 이용해 웹 서버를 공격하는 Kimsuky 그룹
2023-05-15 • Ahnlab • Kimsuky group attacks web servers using Meterpreter •
ASEC reports that Kimsuky attacked a South Korean architectural firm’s Windows IIS web server, likely exploiting an unpatched or poorly managed server to run PowerShell through w3wp.exe. The attacker downloaded a Metasploit Meterpreter backdoor from 45.58.52[.]82 and then used Meterpreter to install an additional Go-based proxy malware. The malware was loaded as a DLL through regsvr32.exe, matching earlier Kimsuky tradecraft, while the newer Go stager and proxy suggest an attempt to evade detection. The proxy accepted IP and port arguments, used an “aPpLe” validation string, and appeared intended to enable later RDP access to the compromised system.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.58.52.82 | 2023-05-15 | 2023-11-01 |
| HASH | 6b2062e61bcb46ce5ff19b329ce31b03 | 2023-05-15 | 2023-05-21 |
| HASH | 000130a373ea4085b87b97a0c7000c86 | 2023-05-15 | 2023-05-21 |