WinRAR 실행압축 파일과 Github 레파지토리를 이용한 APT 공격

2024-04-26 Secu I $eeert=$iuyiti.Replace('yreywetgdfg','');

https://stic.secui.com/main/main/threatInfo?id=225

Thumbnail for WinRAR 실행압축 파일과 Github 레파지토리를 이용한 APT 공격

SECUi observed a domestic APT case delivered through a ZIP archive named like a Korean military studies review package. The archive contained a normal HWP decoy and a malicious WinRAR self-extracting EXE disguised as an HWP-related review file, which displayed the decoy while launching embedded PowerShell. The first PowerShell stage downloaded additional script content from sampleblog365.com, and the second stage collected host information including ipconfig output and Recent-folder listings. The stolen data was uploaded to a GitHub repository path as thumb.db, and repository history showed filenames such as payment request and document-lure names, illustrating use of public developer infrastructure for exfiltration and staging.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8c0b84910816a5d223f53080961bd8b… 2024-04-26 2024-04-26
URL http://www.sampleblog365.com/ar… 2024-04-26 2024-04-26

Related Reports

« Back