Zoom 접속 정보로 위장한 ReconShark
2023-08-21 • Hauri • ReconShark disguised as Zoom access information •
https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=53
Attachments
Hauri reported a Kimsuky malware family called ReconShark that used Zoom meeting-information lures against organizations and individuals handling North Korea-related information. The malware displayed a decoy Zoom document from attacker infrastructure, collected battery and process information from the infected PC, and sent it to command-and-control infrastructure. It then received an AES key to decrypt follow-on download code, adapting execution depending on installed security products such as Bitdefender, Kaspersky, V3, Alyac, and Avast.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | mngrdp.site | 2023-08-21 | 2024-02-28 |
| HASH | ea986b990b17c7ef847b7abf1b108373 | 2023-08-21 | 2023-08-21 |
| URL | https://mngrdp.site/hiro/ca.php… | 2023-08-21 | 2023-08-21 |
| URL | https://mngrdp.site/hiro/ca.php… | 2023-08-21 | 2023-08-21 |
| URL | https://mngrdp.site/hiro/share.… | 2023-08-21 | 2023-08-21 |
| URL | https://mngrdp.site/hiro/r.php | 2023-08-21 | 2023-08-21 |
| URL | https://mngrdp.site/hiro/re.php | 2023-08-21 | 2023-08-21 |
| URL | http://mngrdp.site/hiro/ca.php?… | 2023-08-21 | 2023-08-21 |
| URL | http://mngrdp.site/hiro/d.php?n… | 2023-08-21 | 2023-08-21 |