New Andariel Reconnaissance Tactics Hint At Next Targets
2018-07-16 • Trend Micro •
Trend Micro reported that Andariel compromised South Korean websites to run reconnaissance scripts against visitors before possible follow-on exploitation. The injected JavaScript collected browser type, system language, Flash and Silverlight versions, and ActiveX object availability, extending earlier reconnaissance associated with Operation GoldenAxe. The newer script checked for ActiveX objects tied to South Korean DRM and voice conversion software and also probed local WebSocket ports 45461 and 45462, suggesting interest beyond Internet Explorer-only ActiveX targeting. The activity matters because Andariel had previously used similar pre-exploitation profiling before deploying an ActiveX zero-day, making these compromised sites and collection endpoints useful warning indicators for South Korean public-sector and institutional targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cfcd391eec9fca663afd9a4a152e62a… | 2018-07-16 | 2018-07-16 |
| HASH | e0e30eb5e5ff1e71548c4405d04ce16… | 2018-07-16 | 2018-07-16 |
| HASH | 67a1312768c4ca3379181c0fcc11434… | 2018-07-16 | 2018-07-16 |
| URL | http://adfamc.com/editor/sorak/… | 2018-07-16 | 2018-07-16 |
| URL | http://www.peaceind.co.kr/board… | 2018-07-16 | 2018-07-16 |
| URL | http://adfamc.com/editor/sorak/… | 2018-07-16 | 2018-07-16 |
| URL | http://aega.co.kr/mall/skin/ski… | 2018-07-16 | 2018-07-16 |
| URL | http://alphap1.com/hdd/images/i… | 2018-07-16 | 2018-07-16 |
| DOMAIN | aega.co.kr | 2018-07-16 | 2018-07-16 |
| DOMAIN | adfamc.com | 2018-07-16 | 2018-07-16 |
| DOMAIN | alphap1.com | 2018-05-23 | 2018-07-16 |