韓国水力原子力発電の内部情報流出をまとめてみた

2014-12-23 piyokango A summary of internal information leaks at South Korean Hydro and Nuclear Power Plants

http://d.hatena.ne.jp/Kango/20141223/1419269574

Thumbnail for 韓国水力原子力発電の内部情報流出をまとめてみた

Piyolog's KHNP roundup tracks the 2014 leak and destructive-malware incident at Korea Hydro and Nuclear Power, a Korea Electric Power subsidiary. The timeline says thousands of malware-laden emails were sent to KHNP on December 9, malware was scheduled to run on December 10, internal documents began leaking through Naver Blog and Twitter on December 15-16, and prosecutors later gave an interim assessment that North Korea was involved. The source lists HWP droppers, suspected use of retired employees' private email addresses, source IPs concentrated around Shenyang, and destructive DLL malware detected as Destfallen or Destroyer. The malware functions included a time bomb, MBR overwriting, file wiping for document and archive extensions, and gateway DoS packets containing the phrase "Who am I?"

Indicators of Compromise

Type Value First Seen Last Seen
HASH 54783422cfd7029a26a3f3f5e9087d8a 2014-12-10 2019-03-04
HASH 0fe2d77d52a0008a755c9842ad392fc8 2014-12-23 2014-12-23
EMAIL [email protected] 2014-12-23 2014-12-23
EMAIL [email protected] 2014-12-23 2014-12-23
URL https://www.dropbox.com/s/zgw9d… 2014-12-23 2014-12-23
URL https://www.dropbox.com/s/xh2t1… 2014-12-23 2014-12-23
URL https://www.dropbox.com/s/uh3y1… 2014-12-23 2014-12-23
URL http://pastebin.com/XATiwbdA 2014-12-23 2014-12-23
URL https://www.dropbox.com/s/tdfrn… 2014-12-23 2014-12-23
URL https://www.dropbox.com/s/mvsr0… 2014-12-23 2014-12-23
URL http://pastebin.com/cm8mcm0v 2014-12-23 2014-12-23
HASH f09ea2a841114121f32211faac553e1b 2014-12-10 2014-12-23
HASH 33874577bf54d3c209925c9def880eb9 2014-12-10 2014-12-23
HASH 9daf088fe4c9a9580216e98dbb7d1fca 2014-12-10 2014-12-23
HASH 3ba8a6815f828dfc518a0bdbd27bba5b 2014-12-10 2014-12-23
HASH b5b6e93ab27cec75f07af2a3a6a40926 2014-12-10 2014-12-23
HASH ead682b889218979b1f2f1527227af9b 2014-12-10 2014-12-23
HASH 800866bbab514657969996210bcf727b 2014-12-10 2014-12-23
HASH af792a34548a2038f034ea9a6ff0639a 2014-12-10 2014-12-23
HASH 3ec69ee7135272e5bed3ea5378ade6ee 2014-12-10 2014-12-23

Related Reports

« Back