KimJongRAT/stealer malware analysis

2013-06-10 Malwarelu

https://malware.lu/assets/files/articles/RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf

Attachments

RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf (2 MB)

Thumbnail for KimJongRAT/stealer malware analysis

Malware.lu CERT and itrust analyzed a suspicious PDF named “Draft response letter Slovenia.pdf” that they identify as KimJongRAT/Stealer after it was uploaded to malwr.com in May 2013. The document describes a PDF exploit that deploys sysninit.ocx and a launcher, with sections covering resource manipulation, file creation, .lnk persistence, display of a decoy PDF, and hidden initialization. The analysis also documents DLL injection into explorer.exe, an IAT hook of ntdll.ZwQueryDirectoryFile to hide files from Explorer, obfuscation, and VirtualBox detection. Command-and-control behavior is covered through first and second C&C sections, including a Gmail request creation figure, making the report useful for understanding early RAT deployment, stealth, and communications tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 848d0c4c4f608fdd50735a2f0c41af9… 2013-06-10 2013-06-10
HASH d9313622210409c8ada3a6733b8b556… 2013-06-10 2013-06-10
HASH 2b47119b9c97b736c1c775f4fe62042… 2013-06-10 2013-06-10
HASH 6a9598599055e4ed876ec699b0a91272 2013-06-10 2013-06-10
HASH 26eaac1501c62c470a1a9c615c4d7fb8 2013-06-10 2013-06-10
HASH 86964f449a82b8485feef8a5339d0615 2013-06-10 2013-06-10
HASH 41d7b66062825d41726bb243075f2a0… 2013-06-10 2013-06-10
HASH 60805b352c15413a9ceaabedc8f060ea 2013-06-10 2013-06-10
EMAIL [email protected] 2013-06-10 2013-06-10
URL http://www.jhj.wv4.org/test2/se… 2013-06-10 2013-06-10
URL http://www.test1.wv4.org/ 2013-06-10 2013-06-10
URL http://www.jhj.wv4.org/test1/ 2013-06-10 2013-06-10
URL http://www.jhj.wv4.org/test2/ 2013-06-10 2013-06-10

Related Reports

« Back