Tonto 그룹, DLL Side-Loading 에 Anti-Virus 관련 파일 이용 - ASEC BLOG
Common Information
Type Value
UUID a4b7ff36-5242-4ea2-8f93-fc788f9ed290
Fingerprint d6251b249465f926
Analysis status DONE
Considered CTI value 2
Text language
Published April 19, 2023, 5:18 p.m.
Added to db April 20, 2023, 9:17 a.m.
Last updated Nov. 14, 2024, 10:55 p.m.
Headline Tonto 그룹, DLL Side-Loading 에 Anti-Virus 관련 파일 이용
Title Tonto 그룹, DLL Side-Loading 에 Anti-Virus 관련 파일 이용 - ASEC BLOG
Detected Hints/Tags/Attributes 15/2/16
Source URLs
RSS Feed
Attributes
Details Type #Events CTI Value
Details Domain 3
hairouni.serveblog.net
Details File 6
presentationsettings.exe
Details File 9
slc.dll
Details File 4
1.chm
Details File 3
himtraylcon.exe
Details File 2
kcaseagent64.exe
Details File 15
wsc_proxy.exe
Details File 18
wsc.dll
Details md5 2
59f7a3fe0453ca6d27ba3abe78930fdf
Details md5 2
fe1161885005ac85f89accf703ce27bb
Details md5 2
d5e6dc253a5584b178ae3c758120da4d
Details IPv4 3
92.38.135.212
Details IPv4 3
45.133.194.135
Details MITRE ATT&CK Techniques 227
T1574.002
Details Url 3
https://92.38.135.212/fuat/himtraylcon.exe
Details Url 2
http://45.133.194.135:8080/fuat/kcaseagent64.exe