Wiper Malware Threat Analysis
2013-03-21 • Secure Works •
https://www.secureworks.com/research/wiper-malware-analysis-attacking-korean-financial-sector
Dell SecureWorks analyzed destructive Wiper malware used in the March 20, 2013 attacks that disrupted South Korean broadcasters, banks, and other financial-sector systems. The dropper extracted Windows wiper components, PuTTY SSH/SCP binaries, and a Unix Bash wiper script, then searched stored mRemote or SecureCRT sessions for root SSH credentials to copy and execute the Unix wiper on reachable servers. The Windows wipers overwrote MBR, VBR, logical drives, and files using sample-specific strings such as PRINCPES, HASTATI, and PR!NCPES, with one variant waiting until 14:00 KST on the attack date. The report lists hashes for the dropper, wipers, and dropped tools, notes checks for AhnLab-related artifacts, and emphasizes that the samples lacked C2, backdoor, or data-theft functionality while still causing large-scale destructive impact.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9263e40d9823aecf9388b64de34eae54 | 2013-03-21 | 2013-07-08 |
| HASH | db4bbdc36a78a8807ad9b15a562515c4 | 2013-03-20 | 2013-07-08 |
| HASH | 5fcd6e1dace6b0599429d913850f0364 | 2013-03-20 | 2013-07-08 |
| HASH | 6a702342e8d9911bde134129542a045b | 2013-03-21 | 2013-04-02 |
| HASH | dc789dee20087c5e1552804492b042cd | 2013-03-21 | 2013-04-02 |
| HASH | e45cd9052dd3dd502685dfd9aa2575ca | 2013-03-21 | 2013-04-02 |
| HASH | 0a8032cd6b4a710b1771a080fa09fb87 | 2013-03-20 | 2013-04-02 |
| DOMAIN | stratigossecurity.com | 2013-03-21 | 2013-03-21 |
| IPv4 | 101.106.25.105 | 2013-03-21 | 2013-03-21 |