WinRAR 실행압축 파일과 Github 레파지토리를 이용한 APT 공격
2024-04-26 • Secu I • $eeert=$iuyiti.Replace('yreywetgdfg',''); •
SECUi observed a domestic APT case delivered through a ZIP archive named like a Korean military studies review package. The archive contained a normal HWP decoy and a malicious WinRAR self-extracting EXE disguised as an HWP-related review file, which displayed the decoy while launching embedded PowerShell. The first PowerShell stage downloaded additional script content from sampleblog365.com, and the second stage collected host information including ipconfig output and Recent-folder listings. The stolen data was uploaded to a GitHub repository path as thumb.db, and repository history showed filenames such as payment request and document-lure names, illustrating use of public developer infrastructure for exfiltration and staging.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8c0b84910816a5d223f53080961bd8b… | 2024-04-26 | 2024-04-26 |
| URL | http://www.sampleblog365.com/ar… | 2024-04-26 | 2024-04-26 |