Wiper Malware Threat Analysis

2013-03-21 Secure Works

https://www.secureworks.com/research/wiper-malware-analysis-attacking-korean-financial-sector

Dell SecureWorks analyzed destructive Wiper malware used in the March 20, 2013 attacks that disrupted South Korean broadcasters, banks, and other financial-sector systems. The dropper extracted Windows wiper components, PuTTY SSH/SCP binaries, and a Unix Bash wiper script, then searched stored mRemote or SecureCRT sessions for root SSH credentials to copy and execute the Unix wiper on reachable servers. The Windows wipers overwrote MBR, VBR, logical drives, and files using sample-specific strings such as PRINCPES, HASTATI, and PR!NCPES, with one variant waiting until 14:00 KST on the attack date. The report lists hashes for the dropper, wipers, and dropped tools, notes checks for AhnLab-related artifacts, and emphasizes that the samples lacked C2, backdoor, or data-theft functionality while still causing large-scale destructive impact.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9263e40d9823aecf9388b64de34eae54 2013-03-21 2013-07-08
HASH db4bbdc36a78a8807ad9b15a562515c4 2013-03-20 2013-07-08
HASH 5fcd6e1dace6b0599429d913850f0364 2013-03-20 2013-07-08
HASH 6a702342e8d9911bde134129542a045b 2013-03-21 2013-04-02
HASH dc789dee20087c5e1552804492b042cd 2013-03-21 2013-04-02
HASH e45cd9052dd3dd502685dfd9aa2575ca 2013-03-21 2013-04-02
HASH 0a8032cd6b4a710b1771a080fa09fb87 2013-03-20 2013-04-02
DOMAIN stratigossecurity.com 2013-03-21 2013-03-21
IPv4 101.106.25.105 2013-03-21 2013-03-21

Related Actors

Related Reports

« Back