SK 커뮤니케이션즈 해킹 관련 상세 분석 보고서
2011-08-04 • Hauri • Detailed analysis report on SK Communications hacking •
Attachments
cfile9.uf136A793E4E3BA0FE059C9E.pdf (507 KB)
The SK Communications breach analysis traces a NateOn-themed malware chain that used `nateon.exe` to install `winsvcfs.dll` as a service-based RAT. The loader modified its own PE header so the binary could operate as a DLL, wrote the result under an All Users path, copied `kernel32.dll` timestamps for camouflage, and launched it through `RUNDLL32.EXE` with the `RqSkce` export. The RAT decrypted its strings and C2 settings at runtime, attempted port-80 communication with `nateon.duamlive.com` after checking `download.windowsupdate.com`, and registered persistence through `svchost.exe -k LocalService` service keys. Its command set covered database queries, registry manipulation, network and socket operations, service control, file operations, screenshots, process/module enumeration, command execution, and system power/session actions, supporting the report’s description of malware used in the breach that exposed about 35 million Nate user records.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e3d8ce21bff2dd1882da2775e88a9935 | 2011-08-04 | 2011-08-04 |
| HASH | 461884f1d41e9e0709b40ab2ce5afca7 | 2011-08-04 | 2011-08-04 |