核心工业系统陷入危机?印度核电厂遭受网络攻击事件梳理与分析

2019-10-31 Qihoo360 Is the core industrial system in crisis? Summary and analysis of cyber attacks on Indian nuclear power plants

https://mp.weixin.qq.com/s/haCZK4m3JVpmgxXNMj30hQ

QiAnXin analyzes DTrack samples tied in public reporting to the Kudankulam nuclear plant intrusion in India, including a sample disclosed on VirusTotal with an embedded KKNPP-related username. The report describes an MFC dropper that extracts shellcode, DTrack RAT behavior that encrypts and ZIP-compresses collected files, and related variants with device fingerprinting, encrypted strings, command-file download logic, and multiple persistence methods. Infrastructure and indicators include MD5 hashes, internal IP references, and external URLs such as heromessi.com and hawai-tour.com paths that appear to be hosted on compromised sites. The authors note strong similarities between DTrack code and Kaspersky’s DTrack reporting, and connect ZIP password/code overlap to McAfee’s Operation Troy material, which had been attributed historically to Lazarus Group.

Indicators of Compromise

Type Value First Seen Last Seen
HASH acd7aafa65d0dc4bdb5f04940107087b 2019-10-31 2019-10-31
HASH ebb52f45ff1483e82ff3258b7f086571 2019-10-31 2019-10-31
HASH b7c3039203278bc289fd3756571bd468 2019-10-31 2019-10-31
HASH 4f8091a5513659b2980cb53578d3f798 2019-10-31 2019-10-31
HASH d10781f6b0a420ba0a9addfa5411fd97 2019-10-31 2019-10-31
HASH b5ab935d750be8b5b7c9cf3b87c772ca 2019-10-31 2019-10-31
URL https://factordaily.com/romania… 2019-10-31 2019-10-31
URL http://hawai-tour.com/wp/wp-img… 2019-10-31 2019-10-31
URL http://heromessi.com/wp-public/… 2019-10-31 2019-10-31
DOMAIN hawai-tour.com 2019-10-31 2019-10-31
DOMAIN heromessi.com 2019-10-31 2019-10-31
DOMAIN economictimes.indiatimes.com 2018-08-28 2019-10-31

Related Reports

« Back