SK 커뮤니케이션즈 해킹 관련 상세 분석 보고서

2011-08-04 Hauri Detailed analysis report on SK Communications hacking

http://jyj850714.tistory.com/attachment/[email protected]

Attachments

cfile9.uf136A793E4E3BA0FE059C9E.pdf (507 KB)

The SK Communications breach analysis traces a NateOn-themed malware chain that used `nateon.exe` to install `winsvcfs.dll` as a service-based RAT. The loader modified its own PE header so the binary could operate as a DLL, wrote the result under an All Users path, copied `kernel32.dll` timestamps for camouflage, and launched it through `RUNDLL32.EXE` with the `RqSkce` export. The RAT decrypted its strings and C2 settings at runtime, attempted port-80 communication with `nateon.duamlive.com` after checking `download.windowsupdate.com`, and registered persistence through `svchost.exe -k LocalService` service keys. Its command set covered database queries, registry manipulation, network and socket operations, service control, file operations, screenshots, process/module enumeration, command execution, and system power/session actions, supporting the report’s description of malware used in the breach that exposed about 35 million Nate user records.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e3d8ce21bff2dd1882da2775e88a9935 2011-08-04 2011-08-04
HASH 461884f1d41e9e0709b40ab2ce5afca7 2011-08-04 2011-08-04

Related Reports

« Back