The HeartBeat APT Campaign

2013-01-03 Trend Micro

https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2012/wp_the-heartbeat-apt-campaign.pdf

Attachments

wp_the-heartbeat-apt-campaign.pdf (3 MB)

Trend Micro’s HeartBeat research describes a targeted campaign that had pursued South Korean government-related organizations and communities since at least 2009. Identified victims included a national policy research institute, a branch of the South Korean armed forces, small business-sector organizations, and branches of the South Korean government. The activity used tailored campaign operations to deliver a RAT component, first found in a Korean newspaper company network in June 2012, with earlier malware evidence dating to November 2009. The paper focuses on the attack vector, RAT behavior, persistence, command-and-control communications, campaign codes, and relationships among C2 domains, IPs, and campaigns, giving defenders a basis for tracking victimology and infrastructure over time.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d1a2253361045f91ed1902e9ffe2cec3 2013-01-03 2013-01-03
HASH aab129ffd3bf5ceeae2e0f332217bebc 2013-01-03 2013-01-03
HASH 7f1a633384ec97fae9d95d1df9e1135a 2013-01-03 2013-01-03
HASH 8816c5be1305488019769c81259dad2a 2013-01-03 2013-01-03
HASH 874025a66c2b9d9831c03d1bc114876a 2013-01-03 2013-01-03
HASH b1e47ecd68c1c151866cec275716aa67 2013-01-03 2013-01-03
HASH 51274cefb01cee981a09db83c984213d 2013-01-03 2013-01-03
HASH fcf42cadb3a932989c8e2b29cef68861 2013-01-03 2013-01-03
HASH f947e63b14853a69b8ed2648869b5e10 2013-01-03 2013-01-03
HASH ef2bc66ea69327d11d1859af26f5aef9 2013-01-03 2013-01-03
HASH 20bb652e1d2679ed230102aa9676eca0 2013-01-03 2013-01-03
HASH c5c0fea23138cddab96fe22b657f9132 2013-01-03 2013-01-03
HASH 4046dec1aa0eebb01fe7469184a95398 2013-01-03 2013-01-03
HASH 86547d674e7c7da55e8cae359819832f 2013-01-03 2013-01-03
HASH 8e50af054d2c0b45c88082d53c4fc423 2013-01-03 2013-01-03
HASH ba370b17dc9eb1d1e1c3187f0768064f 2013-01-03 2013-01-03
HASH 7c6b44d8d87898e7e5deeeb1961b5ae6 2013-01-03 2013-01-03
HASH 5ec175512ba3c6e78597af48bbe6ca60 2013-01-03 2013-01-03
HASH 6d205e78fb7730066c116b0c2dffa398 2013-01-03 2013-01-03
DOMAIN snrp.uglyas.com 2013-01-03 2013-01-03
« Back