Dark South Korea Total War Review
2013-04-02 • Zataz •
https://eromang.zataz.com/2013/04/02/dark-south-korea-total-war-review/
The March 2013 Dark South Korea attack disrupted South Korean banks and broadcasters including KBS, MBC, YTN, Nonghyup, Shinhan, and Cheju, with roughly 47,800 systems reported impacted. The excerpt separates the activity into wiper, drop-and-wipe, drop-and-deface, drop-and-backdoor, and uncertain sample categories, emphasizing that not every recovered malware sample can be confidently tied to the campaign. AhnLab Policy Center and HAURI ViRobot ISMS asset-management infrastructure were reported as abuse points for mass malware delivery, with later reporting pointing to an AhnLab authentication-bypass weakness rather than only stolen credentials. The malware evidence includes Trojan.Jokra-related droppers and wipers, mapped network-drive overwriting behavior, defacement components, build timestamps, MD5 hashes, and a small set of suspicious download URLs, giving defenders concrete artifacts while also warning against over-linking unrelated samples.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f0e045210e3258dad91d7b6b4d64e7f3 | 2013-04-02 | 2020-03-09 |
| HASH | 9263e40d9823aecf9388b64de34eae54 | 2013-03-21 | 2013-07-08 |
| HASH | db4bbdc36a78a8807ad9b15a562515c4 | 2013-03-20 | 2013-07-08 |
| HASH | 5fcd6e1dace6b0599429d913850f0364 | 2013-03-20 | 2013-07-08 |
| HASH | a03ae3a480dd17134b04dbc5e62bf57b | 2013-04-02 | 2013-04-24 |
| HASH | 50e03200c3a0becbf33b3788dac8cd46 | 2013-03-29 | 2013-04-24 |
| HASH | 2f9af723e807ff44c2684e5d644ebe46 | 2013-04-02 | 2013-04-02 |
| HASH | e4f66c3cd27b97649976f6f0daad9032 | 2013-04-02 | 2013-04-02 |
| HASH | e823221609b37e99fbbce5b493a02f68 | 2013-04-02 | 2013-04-02 |
| URL | http://www.skymom.co.kr/rgboard… | 2013-04-02 | 2013-04-02 |
| URL | http://www.anulaibar.com/e107/e… | 2013-04-02 | 2013-04-02 |
| DOMAIN | xsecure-lab.com | 2013-04-02 | 2013-04-02 |
| HASH | 6a702342e8d9911bde134129542a045b | 2013-03-21 | 2013-04-02 |
| HASH | dc789dee20087c5e1552804492b042cd | 2013-03-21 | 2013-04-02 |
| HASH | e45cd9052dd3dd502685dfd9aa2575ca | 2013-03-21 | 2013-04-02 |
| HASH | 0a8032cd6b4a710b1771a080fa09fb87 | 2013-03-20 | 2013-04-02 |