核心工业系统陷入危机?印度核电厂遭受网络攻击事件梳理与分析
2019-10-31 • Qihoo360 • Is the core industrial system in crisis? Summary and analysis of cyber attacks on Indian nuclear power plants •
QiAnXin analyzes DTrack samples tied in public reporting to the Kudankulam nuclear plant intrusion in India, including a sample disclosed on VirusTotal with an embedded KKNPP-related username. The report describes an MFC dropper that extracts shellcode, DTrack RAT behavior that encrypts and ZIP-compresses collected files, and related variants with device fingerprinting, encrypted strings, command-file download logic, and multiple persistence methods. Infrastructure and indicators include MD5 hashes, internal IP references, and external URLs such as heromessi.com and hawai-tour.com paths that appear to be hosted on compromised sites. The authors note strong similarities between DTrack code and Kaspersky’s DTrack reporting, and connect ZIP password/code overlap to McAfee’s Operation Troy material, which had been attributed historically to Lazarus Group.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | acd7aafa65d0dc4bdb5f04940107087b | 2019-10-31 | 2019-10-31 |
| HASH | ebb52f45ff1483e82ff3258b7f086571 | 2019-10-31 | 2019-10-31 |
| HASH | b7c3039203278bc289fd3756571bd468 | 2019-10-31 | 2019-10-31 |
| HASH | 4f8091a5513659b2980cb53578d3f798 | 2019-10-31 | 2019-10-31 |
| HASH | d10781f6b0a420ba0a9addfa5411fd97 | 2019-10-31 | 2019-10-31 |
| HASH | b5ab935d750be8b5b7c9cf3b87c772ca | 2019-10-31 | 2019-10-31 |
| URL | https://factordaily.com/romania… | 2019-10-31 | 2019-10-31 |
| URL | http://hawai-tour.com/wp/wp-img… | 2019-10-31 | 2019-10-31 |
| URL | http://heromessi.com/wp-public/… | 2019-10-31 | 2019-10-31 |
| DOMAIN | hawai-tour.com | 2019-10-31 | 2019-10-31 |
| DOMAIN | heromessi.com | 2019-10-31 | 2019-10-31 |
| DOMAIN | economictimes.indiatimes.com | 2018-08-28 | 2019-10-31 |