« 2018 »

171 reports

2018-09-21 • v3lo

The source analyzes a Korean HWP malware sample described as similar to earlier ROKRAT activity, with VirusTotal showing the Hangul document as undetected at the time. The infection chain converts shellcode into PE files under the Temp directory, creates …

#RokRAT
2018-09-06 • USJustice

The excerpt is a U.S. federal criminal complaint against Park Jin Hyok alleging conspiracy and wire-fraud-related computer intrusion activity from at least 2014 through 2017. Its table of contents links the case to North Korean computer networks, Brambul,…

#WannaCry #Blockbuster #BangSwift
2018-08-29 • kino

A malicious file themed around the AltPlanet coin used a familiar EPS vulnerability to initiate the attack. The downloaded file was encrypted with 0xAA and identified in the excerpt as Manuscrypt. The listed command-and-control infrastructure includes dgj…

#Manuscrypt