Piece of dragon's scales

2021-12-30 kino

https://sfkino.tistory.com/80

A Korean malware-analysis post tracks ongoing Kimsuky/Thallium activity using the GoldDragon/BravePrince cluster, noting a newer sample that keeps the usual daum-mail information-theft behavior while adding encoded DLL and API-name resolution. The author also describes a related information-stealer module that collects system, network, process, file-list, and browser credential data into an AppData working directory and appears designed to be launched by another component. A third case links the same encoded-string intelligence pivot to a .NET dropper that deploys privilege-elevation tooling, disables Windows Defender, installs a Quasar RAT-based payload, and persists through scheduled tasks or Run keys. Representative infrastructure and indicators include blog.daum[.]net/casalesmedia/pages/category, 222.122.79.232 on ports 8080 and 443, and hashes for the analyzed samples.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e8bef41ed7d0704d9206880ee0f30b5… 2021-12-30 2021-12-30
HASH 3a7355417ebfdb5067582916bbaf0f15 2021-12-30 2021-12-30
HASH 8edfa086de4dfdc93c0551bbb08cd5a8 2021-12-30 2021-12-30
HASH 4b1b5bed35bc676e835de14ee033339… 2021-12-30 2021-12-30
HASH 237deba138355bfb448e74bfb68fc86… 2021-12-30 2021-12-30
HASH e11e2425c62f34ebb3f640baeefb67d5 2021-12-30 2021-12-30
HASH 322ad36bf0db8244b64e2d3afc1ccf5… 2021-12-30 2021-12-30
HASH 7dc6f8aaaf4431c365564a51dd37c14… 2021-12-30 2021-12-30
HASH 0cf7e1268e8652d841b7bda784707e4… 2021-12-30 2021-12-30
HASH 51a92bd57ece4a107dacabf2639b6fa… 2021-12-30 2021-12-30
HASH c3885f3c1001a53eb4fbbb4b5f42163e 2021-12-30 2021-12-30
HASH e647b3366dc836c1f63bdc5ba2aef3a9 2021-12-30 2021-12-30
HASH 3903958eb28632aa58e455eb87482d1… 2021-12-30 2021-12-30
HASH a7b0711b45081768817e85d6fc76e23… 2021-12-30 2021-12-30
IPv4 222.122.79.232 2021-12-30 2021-12-30
IPv4 14.47.189.243 2021-12-30 2021-12-30
HASH 5e3907e9e2ed8ff12bb4e96b52401d8… 2021-11-10 2021-12-30

Related Actors

Related Reports

« Back