New Andariel Reconnaissance Tactics Hint At Next Targets

2018-07-16 Trend Micro

https://blog.trendmicro.com/trendlabs-security-intelligence/new-andariel-reconnaissance-tactics-hint-at-next-targets/

Thumbnail for New Andariel Reconnaissance Tactics Hint At Next Targets

Trend Micro reported that Andariel compromised South Korean websites to run reconnaissance scripts against visitors before possible follow-on exploitation. The injected JavaScript collected browser type, system language, Flash and Silverlight versions, and ActiveX object availability, extending earlier reconnaissance associated with Operation GoldenAxe. The newer script checked for ActiveX objects tied to South Korean DRM and voice conversion software and also probed local WebSocket ports 45461 and 45462, suggesting interest beyond Internet Explorer-only ActiveX targeting. The activity matters because Andariel had previously used similar pre-exploitation profiling before deploying an ActiveX zero-day, making these compromised sites and collection endpoints useful warning indicators for South Korean public-sector and institutional targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cfcd391eec9fca663afd9a4a152e62a… 2018-07-16 2018-07-16
HASH e0e30eb5e5ff1e71548c4405d04ce16… 2018-07-16 2018-07-16
HASH 67a1312768c4ca3379181c0fcc11434… 2018-07-16 2018-07-16
URL http://adfamc.com/editor/sorak/… 2018-07-16 2018-07-16
URL http://www.peaceind.co.kr/board… 2018-07-16 2018-07-16
URL http://adfamc.com/editor/sorak/… 2018-07-16 2018-07-16
URL http://aega.co.kr/mall/skin/ski… 2018-07-16 2018-07-16
URL http://alphap1.com/hdd/images/i… 2018-07-16 2018-07-16
DOMAIN aega.co.kr 2018-07-16 2018-07-16
DOMAIN adfamc.com 2018-07-16 2018-07-16
DOMAIN alphap1.com 2018-05-23 2018-07-16

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back