Suspected APT37 New Attack Weapon Fakecheck Analysis Report

2023-08-25 Knownsec

https://paper.seebug.org/3012/

Thumbnail for Suspected APT37 New Attack Weapon Fakecheck Analysis Report

Knownsec 404 analyzed malicious CHM samples using Korean-language decoys themed around insurance, securities, finance, and communications bills, with targeting directed at South Korea. The CHM attack chain decompiled itself, released files under a public user directory, executed a JSE script, downloaded a payload as alg.exe, and showed code overlap with CHM activity previously disclosed by AhnLab. The final payload, named FakeCheck by the researchers, is a .NET RAT that collects host, disk, browser, bookmark, saved-password, and recent-file data, stores the results under the public pictures directory, uploads them to C2, and executes commands received from the server. Although some researchers attributed the activity to APT37, Knownsec states that the observed samples and TTPs do not provide direct evidence for that attribution and could represent new APT37 tradecraft or another actor using similar CHM techniques.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 01e7405ddd5545ffb4a57040acc4b6f… 2023-08-25 2023-09-13
HASH a1f6ae788bf3f9ae17893f3b12d557f… 2023-08-25 2023-09-13
HASH 012063e0b7b4f7f3ce50574797112f9… 2023-08-25 2023-09-13
HASH f5e46e18facc6f8fde6658b96dcd379… 2023-08-25 2023-09-13
HASH 578689cb4b06c4d3f1850e4379c4b31… 2023-08-25 2023-09-13
URL https://tosals.ink/uEH5J.html 2023-07-21 2023-08-30
DOMAIN tosals.ink 2023-07-21 2023-08-30
HASH 37feb1d71c6458f71b27dc1ba7cb436… 2023-08-25 2023-08-25
HASH 2b2583019d83e657c219dd6510060f9… 2023-08-25 2023-08-25
URL https://oebil.lat/zyofl 2023-08-25 2023-08-25
URL https://giath.xyz/maiqt 2023-08-25 2023-08-25
URL https://bajut.pro/jdkvr 2023-08-25 2023-08-25
DOMAIN for.net 2023-08-25 2023-08-25
DOMAIN oebil.lat 2023-08-25 2023-08-25
DOMAIN giath.xyz 2023-08-25 2023-08-25
DOMAIN bajut.pro 2023-08-25 2023-08-25
URL https://crilts.cfd/cdeeb 2023-07-20 2023-08-25
DOMAIN crilts.cfd 2023-07-20 2023-08-25

Related Actors

Related Reports

« Back