Red Eyes Hacking Group 상세 분석
2018-04-03 • Ahnlab • Red Eyes Hacking Group Detailed Analysis •
http://download.ahnlab.com/kr/site/library/[Report]Red_Eyes_Hacking_Group_kor.pdf
Attachments
AhnLab profiles the Red Eyes group, also known as Geumseong121, Group 123, ScarCruft, APT37, Reaper, and Ricochet Chollima, as a cluster targeting defectors, North Korean human-rights activists, North Korea researchers, journalists, and some military-themed lures. The group commonly delivered malicious documents by email or mobile messenger, using HWP EPS exploitation, embedded VBS or EXE files, MS Office documents, DDE, and a Flash Player zero-day later identified as CVE-2018-4878. Malware families described in the report include Reloader or DocPrint loaders, Reloaderx information stealers and downloaders, the Redoor or DogCall backdoor, and a wiper that damages hard disks and displays an "Are you Happy?" message after reboot. AhnLab also notes distinctive PDB paths and strings such as First, Happy, Work, and pad-2 artifacts, using them to discuss possible links to earlier 2015-2016 activity including Operation ProgamsByMe.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7ca1e08fc07166a440576d1af0a15bb1 | 2018-04-03 | 2023-05-23 |
| HASH | 44bdeb6c0af7c36a08c64e31ceadc63c | 2018-04-03 | 2023-05-23 |
| HASH | 6cec7de9d4797895775e2add9d6855ba | 2018-04-03 | 2018-08-14 |
| HASH | 9cd11aa7872f9cba98264113d3d72893 | 2018-04-03 | 2018-08-14 |
| HASH | f793deeee9dc4235d228e68d27057dcc | 2018-04-03 | 2018-08-14 |
| HASH | 89c3254aa577d3788f0f402fe6e5a855 | 2018-04-03 | 2018-08-14 |
| HASH | 8b55d52b12cf319d9785ad8eeeade5ea | 2018-04-03 | 2018-08-14 |
| HASH | 9f1e60e0c794aa3f3bdf8a6645ccabdc | 2018-04-03 | 2018-08-14 |
| HASH | f0a5385d0d9f7c546b25a7448ca5b1c9 | 2018-04-03 | 2018-08-14 |
| HASH | 2f0492f53d348bea993b7ae5983508a6 | 2018-04-03 | 2018-08-14 |
| HASH | 06ae5d62d56f21cd2676989743b9626c | 2018-04-03 | 2018-08-14 |
| HASH | 2fdbb9a500143a2dd3d226a1cc3e45b5 | 2018-04-03 | 2018-08-14 |
| HASH | 49d30adaab769fbea2ef69e09c6598c5 | 2018-04-03 | 2018-08-14 |
| HASH | 9ac2ffd3f1cea2e01ed77c2e7b4a29e7 | 2018-04-03 | 2018-08-14 |
| HASH | d00e3196bc847e63fc4b255e8ab06d1c | 2018-04-03 | 2018-08-14 |
| HASH | f613c9276d0deb19d0959aa2fbfc737c | 2018-04-03 | 2018-08-14 |
| DOMAIN | byline.network | 2018-04-03 | 2018-08-14 |
| DOMAIN | ush.co.kr | 2018-04-03 | 2018-08-14 |
| HASH | 0ff0f3f0722dd122a0f5c3d4c7752675 | 2018-02-27 | 2018-08-14 |
| HASH | fc0a9850f7b6a91f7757d64c86cfc141 | 2018-02-27 | 2018-08-14 |
| HASH | 42f216cc32cf2b14e6daea0816da8c50 | 2018-04-03 | 2018-04-03 |
| HASH | 5ef03b48b4ae68c572028c72572444d2 | 2018-04-03 | 2018-04-03 |
| DOMAIN | biz.khan.co.kr | 2018-04-03 | 2018-04-03 |