ScarCruft针对韩国金融、高校下发Chinotto后门的攻击活动分析 - 安恒威胁情报中心
2023-08-30 • 安恒信息 • ScarCruft analysis of attack activities targeting South Korean financial institutions and universities with Chinotto backdoors - Anheng Threat Intelligence Center •
https://starmap.dbappsecurity.com.cn/blog/articles/2023/08/30/scarcruft-deliver-chinotto/
ScarCruft targeted South Korean financial institutions, universities, and individual users with ZIP/RAR lures that delivered Chinotto PowerShell backdoors or an InfoStealer. The campaign used Korean financial and insurance themes, including encrypted decoy documents that required a target birthdate or password, and malicious LNK/CHM files hosted on public websites. One chain unpacked a fake XLSX LNK and BAT script, persisted via `UserProfileSafeBackup.bat`, invoked mshta, and contacted `75.119.136.207` and `bian0151.cafe24.com` for Chinotto commands. Other CHM chains masqueraded as HanaCard, KBank, DB Insurance, or university-related documents, with the InfoStealer collecting browser, recent-file, and registry artifacts before uploading them to attacker infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ableinfo.co.kr | 2023-08-30 | 2025-01-12 |
| HASH | fa03b0248a109a86eaddba108ebfcb14 | 2023-08-30 | 2023-12-01 |
| HASH | 16a34b0e194b3f825a19db5363df4cca | 2023-08-30 | 2023-12-01 |
| HASH | 0eb8db3cbde470407f942fd63afe42b8 | 2023-08-22 | 2023-09-06 |
| HASH | 2d444b6f72c8327d1d155faa2cca7fd7 | 2023-08-22 | 2023-09-06 |
| URL | http://bian0151.cafe24.com/admi… | 2023-08-22 | 2023-09-06 |
| DOMAIN | bian0151.cafe24.com | 2023-08-22 | 2023-09-06 |
| IPv4 | 75.119.136.207 | 2023-07-11 | 2023-09-06 |
| HASH | 74dd8338fedcb9c1d098b38e19a65d48 | 2023-08-30 | 2023-08-30 |
| HASH | c52f99555875c34bd1bd531ffab65234 | 2023-08-30 | 2023-08-30 |
| URL | http://ableinfo.co.kr/member/ | 2023-08-30 | 2023-08-30 |
| URL | http://bian0151.cafe24.com/memb… | 2023-08-30 | 2023-08-30 |
| HASH | 66165dfb784cbcb442e4767f0ca4f469 | 2023-08-22 | 2023-08-30 |
| URL | https://tosals.ink/uEH5J.html | 2023-07-21 | 2023-08-30 |
| DOMAIN | tosals.ink | 2023-07-21 | 2023-08-30 |
| URL | https://atusay.lat/kxydo | 2023-07-20 | 2023-08-30 |
| DOMAIN | atusay.lat | 2023-07-20 | 2023-08-30 |