« 2014 »

18 reports

2014-12-31 • KRCERT

KISA/KRCERT's 2014 Malware Analysis report examines more than 500 malware samples to support similarity analysis, rapid variant detection, and incident response for Korean cyber incidents. The DPRK-relevant sections cover 7.7 DDoS, 3.4 DDoS, 3.20 cyber-te…

#DarkSeoul #6.25CyberTerror #3.4DDoS #7.7DDoS
2014-12-23 • Trend Micro

Trend Micro analyzed TROJ_WHAIM.A, a destructive MBR wiper used against a Korean power-plant target and believed to have reached systems partly through malicious Hangul Word Processor files delivered with social-engineering lures. The malware checked whet…

#Wiper #KHNP
2014-12-19 • USCISA

US-CERT reports destructive malware activity against a major entertainment company using an SMB worm tool with multiple components for propagation, access, proxying, and wiping. The worm brute-forces Windows SMB shares on port 445, copies itself to reacha…

#Wiper
2014-12-17 • Cisco Talos

Cisco Talos analyzed a wiper malware variant to improve network detection for beaconing behavior from the disk-wiping component. The team examined related samples, modified hard-coded command-and-control addresses to a local decoy environment, and shorten…

#Wiper
2014-05-07 • ESTSecurity

ALYac analyzed a malicious HWP document judged to resemble previously reported Kimsuky-style activity targeting Korean organizations. The document abuses a Hancom Office vulnerability through hidden HWP sections with abnormally large paragraph text data, …

#Kimsuky