PC방에서 플레이되는 고포류 게임을 노리는 악성코드 정보

2018-09-14 hummingbird Malware information targeting high-definition games played in PC rooms

https://hummingbird.tistory.com/6707

Thumbnail for PC방에서 플레이되는 고포류 게임을 노리는 악성코드 정보

A Korean malware operation targeted public PC-room environments where users played go-stop, poker, Baduki, Matgo, Vanilla Game, and related online gambling/card games for financial gain. The installer or updater dropped syswnt.exe, cleaned prior components and the SQLSVC service, then contacted a shortened URL that led to a Japan-hosted server used to download sqlservice.exe and GInsert.exe. sqlservice.exe installed itself as the SQLSVC service under Common Files\Services, created additional Windows modules, and launched or injected activity through Windows Sidebar to hide execution and resist termination. GInsert.exe appeared designed to interfere with Ghost recovery images, while other modules checked PC-room management software and disabled recovery tools such as Shadow Defender and Norton Ghost to improve persistence. The malware’s apparent purpose was to join targeted game rooms, inspect opponents’ cards, and improve win rates to acquire in-game money.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c23fbe7cc6f185123fb9c8001fe6430… 2018-09-14 2018-09-14
HASH 7242cd786e494064cce7ebf5d5f0dc9… 2018-09-14 2018-09-14
HASH 457f1e6462c9b8abff3adc578e6d363… 2018-09-14 2018-09-14
HASH e8ade2580be93921b51ff889130c346… 2018-09-14 2018-09-14
HASH 77c1304dbee0ec0c42e01e781ec21bc… 2018-09-14 2018-09-14
HASH f89ff7fb3e39fba9aeb723690afb6f9… 2018-09-14 2018-09-14
HASH 2a09963cbcc2634a87513b9a7ee519c… 2018-09-14 2018-09-14
HASH 3a7fa60a969d9a51a570e74d5ee35a1… 2018-09-14 2018-09-14
« Back