Overview of AppleSeed Dropper
2022-06-05 • Cyber And Ramen •
https://cyberandramen.net/2022/06/05/overview-of-appleseed-dropper/
Cyber and Ramen analyzes an AppleSeed dropper tied to Kimsuky activity and distributed as a fake router firmware upgrade installer. The sample shows a decoy upgrade prompt and opens iptime.com while creating files under AppData and ProgramData, silently invoking regsvr32, and using mshta to contact leomin.dothome.co[.]kr/update/?mode=login. The chain creates self-deleting BAT files and establishes persistence through an AutoUpdate DLL registered under the current user Run key. The hunting guidance focuses on mshta URL execution, executable creation in suspicious user paths, silent regsvr32 use, and YARA or network signatures for the dropper, backdoor, and update endpoint.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 851e33373114fef45d0fe28c6934fa73 | 2022-05-31 | 2022-07-08 |
| DOMAIN | leomin.dothome.co.kr | 2022-05-31 | 2022-07-08 |
| YARA | NK_APT_AppleSeed_Backdoor | 2022-06-05 | 2022-06-05 |
| YARA | NK_APT_AppleSeed_Dropper | 2022-06-05 | 2022-06-05 |
| HASH | e240465ca0c31373dc7f1af2bfc08bd… | 2022-06-05 | 2022-06-05 |
| HASH | e0ea745b9d6fe7c222a0ee4962905f9… | 2022-06-05 | 2022-06-05 |
| URL | http://leomin.dothome.co.kr/upd… | 2022-05-31 | 2022-06-05 |