TDrop2 Attacks Suggest Dark Seoul Attackers Return

2015-11-18 Paloalto Networks

https://researchcenter.paloaltonetworks.com/2015/11/tdrop2-attacks-suggest-dark-seoul-attackers-return/

Thumbnail for TDrop2 Attacks Suggest Dark Seoul Attackers Return

Unit 42 reports TDrop2 activity in 2015 that closely resembled the Dark Seoul and Operation Troy toolset, while noting that the available evidence was insufficient to conclusively prove the same operators. The observed attack targeted the European transportation and logistics sector through a trojanized industrial-control security-camera video player hosted by a legitimate software distributor. TDrop2 installs the expected video player while running malware that uses process hollowing, retrieves a second-stage payload disguised as an image with an altered "DW" PE header, and executes reconnaissance and download commands. Network traffic uses encryption plus a custom base64 alphabet, and similarities to Operation Troy include shared encoding behavior, string decryption routines, and a matching POST separator. The report also notes that the C2 servers were compromised websites in South Korea and Europe, and that the analyzed samples did not show the destructive wiping behavior associated with the original Dark Seoul incident.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 43eb1b6bf1707e55a39e87985eda455… 2015-11-18 2015-11-23
HASH a02e1cb1efbe8f3551cc3a4b452c2b7… 2015-11-18 2015-11-23
DOMAIN mcm-yachtmanagement.com 2015-11-18 2015-11-23
HASH 353a1288b1f8866af17cd7dffb8b202… 2015-11-18 2015-11-18
HASH 52d465e368d2cb7dbf7d478ebadb367… 2015-11-18 2015-11-18
HASH 486141d174acec27a4139c4593362bd… 2015-11-18 2015-11-18
HASH 9d84e173796657162790377be2303b5… 2015-11-18 2015-11-18
HASH 1dee9b9d2e390f217cf19e63cdc3e53… 2015-11-18 2015-11-18
HASH c1cf57f2bdec8c9b650dfaba0427d12… 2015-11-18 2015-11-18
HASH c1a7b065555b833f76d87b54f1dd2ed… 2015-11-18 2015-11-18
HASH 8e84f93fd0e00acba0e1c4b1c1cef44… 2015-11-18 2015-11-18
HASH a15aafcc79cc66ce7b45113ceff8922… 2015-11-18 2015-11-18
HASH b323d4c3bef99742dda27df3bf07a46… 2015-11-18 2015-11-18
HASH 4a11e0453af1155262775e182e5889f… 2015-11-18 2015-11-18
HASH bc724f66807e2f9c9cab946a3e97da5… 2015-11-18 2015-11-18
HASH 52939b9ec4bc451172fa1c581018519… 2015-11-18 2015-11-18
HASH 4df8a104c9d992c6ea6bd682f86c96d… 2015-11-18 2015-11-18
HASH a30eb5774fe309044467a6a90355cc6… 2015-11-18 2015-11-18
HASH dbb0f061dd29b3f69d5fe48e3827e27… 2015-11-18 2015-11-18
HASH 2e500b2f160f927b1140fb105b83300… 2015-11-18 2015-11-18
HASH 591eb8ce448ab95b28a043943bd9de9… 2015-11-18 2015-11-18
HASH 971fd9ae00ffce5738670ec26bca6cf… 2015-11-18 2015-11-18

Related Reports

« Back