Dark South Korea Total War Review

2013-04-02 Zataz

https://eromang.zataz.com/2013/04/02/dark-south-korea-total-war-review/

The March 2013 Dark South Korea attack disrupted South Korean banks and broadcasters including KBS, MBC, YTN, Nonghyup, Shinhan, and Cheju, with roughly 47,800 systems reported impacted. The excerpt separates the activity into wiper, drop-and-wipe, drop-and-deface, drop-and-backdoor, and uncertain sample categories, emphasizing that not every recovered malware sample can be confidently tied to the campaign. AhnLab Policy Center and HAURI ViRobot ISMS asset-management infrastructure were reported as abuse points for mass malware delivery, with later reporting pointing to an AhnLab authentication-bypass weakness rather than only stolen credentials. The malware evidence includes Trojan.Jokra-related droppers and wipers, mapped network-drive overwriting behavior, defacement components, build timestamps, MD5 hashes, and a small set of suspicious download URLs, giving defenders concrete artifacts while also warning against over-linking unrelated samples.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f0e045210e3258dad91d7b6b4d64e7f3 2013-04-02 2020-03-09
HASH 9263e40d9823aecf9388b64de34eae54 2013-03-21 2013-07-08
HASH db4bbdc36a78a8807ad9b15a562515c4 2013-03-20 2013-07-08
HASH 5fcd6e1dace6b0599429d913850f0364 2013-03-20 2013-07-08
HASH a03ae3a480dd17134b04dbc5e62bf57b 2013-04-02 2013-04-24
HASH 50e03200c3a0becbf33b3788dac8cd46 2013-03-29 2013-04-24
HASH 2f9af723e807ff44c2684e5d644ebe46 2013-04-02 2013-04-02
HASH e4f66c3cd27b97649976f6f0daad9032 2013-04-02 2013-04-02
HASH e823221609b37e99fbbce5b493a02f68 2013-04-02 2013-04-02
URL http://www.skymom.co.kr/rgboard… 2013-04-02 2013-04-02
URL http://www.anulaibar.com/e107/e… 2013-04-02 2013-04-02
DOMAIN xsecure-lab.com 2013-04-02 2013-04-02
HASH 6a702342e8d9911bde134129542a045b 2013-03-21 2013-04-02
HASH dc789dee20087c5e1552804492b042cd 2013-03-21 2013-04-02
HASH e45cd9052dd3dd502685dfd9aa2575ca 2013-03-21 2013-04-02
HASH 0a8032cd6b4a710b1771a080fa09fb87 2013-03-20 2013-04-02

Related Reports

« Back