KimJongRAT/stealer malware analysis
2013-06-10 • Malwarelu •
https://malware.lu/assets/files/articles/RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf
Attachments
Malware.lu CERT and itrust analyzed a suspicious PDF named “Draft response letter Slovenia.pdf” that they identify as KimJongRAT/Stealer after it was uploaded to malwr.com in May 2013. The document describes a PDF exploit that deploys sysninit.ocx and a launcher, with sections covering resource manipulation, file creation, .lnk persistence, display of a decoy PDF, and hidden initialization. The analysis also documents DLL injection into explorer.exe, an IAT hook of ntdll.ZwQueryDirectoryFile to hide files from Explorer, obfuscation, and VirtualBox detection. Command-and-control behavior is covered through first and second C&C sections, including a Gmail request creation figure, making the report useful for understanding early RAT deployment, stealth, and communications tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 848d0c4c4f608fdd50735a2f0c41af9… | 2013-06-10 | 2013-06-10 |
| HASH | d9313622210409c8ada3a6733b8b556… | 2013-06-10 | 2013-06-10 |
| HASH | 2b47119b9c97b736c1c775f4fe62042… | 2013-06-10 | 2013-06-10 |
| HASH | 6a9598599055e4ed876ec699b0a91272 | 2013-06-10 | 2013-06-10 |
| HASH | 26eaac1501c62c470a1a9c615c4d7fb8 | 2013-06-10 | 2013-06-10 |
| HASH | 86964f449a82b8485feef8a5339d0615 | 2013-06-10 | 2013-06-10 |
| HASH | 41d7b66062825d41726bb243075f2a0… | 2013-06-10 | 2013-06-10 |
| HASH | 60805b352c15413a9ceaabedc8f060ea | 2013-06-10 | 2013-06-10 |
| [email protected] | 2013-06-10 | 2013-06-10 | |
| URL | http://www.jhj.wv4.org/test2/se… | 2013-06-10 | 2013-06-10 |
| URL | http://www.test1.wv4.org/ | 2013-06-10 | 2013-06-10 |
| URL | http://www.jhj.wv4.org/test1/ | 2013-06-10 | 2013-06-10 |
| URL | http://www.jhj.wv4.org/test2/ | 2013-06-10 | 2013-06-10 |