« Reports in 2013 »

30 reports

2013-04-24 • Malware-reversing

The excerpt is a sample catalog rather than a full malware analysis, grouping related tools by PDB/debug strings: Concealment Troy, Http Dr0pper, Http Troy, PDF Exploit, TDrop, and additional package parts. It records PE timestamps from 2011-2013, MD5 has…

#DarkSeoul
2013-04-10 • Issuemakers Lab

IssueMakersLab attributed the March 20 attacks on South Korean broadcasters and banks to a hacker group it said had conducted a long-running campaign against South Korea since 2007. The report connected the March 2013 activity to earlier operations throug…

#1Mission
2013-04-10 • KRCERT

A South Korean joint civilian-government-military investigation linked the March 2013 broadcast and financial-sector destructive attacks to methods previously associated with North Korean operations, while describing the attribution as based on accumulate…

#DarkSeoul
2013-03-22 • Stolen Byte

WOWHACKER Group analyzed malware used in the March 20, 2013 South Korea cyberattack. The binary dynamically loads Windows libraries and APIs, checks for a file mapping marker to avoid repeat execution, kills security related processes such as pasvc.exe an…

#DarkSeoul #Wiper
2013-03-21 • Secure Works

Dell SecureWorks analyzed destructive Wiper malware used in the March 20, 2013 attacks that disrupted South Korean broadcasters, banks, and other financial-sector systems. The dropper extracted Windows wiper components, PuTTY SSH/SCP binaries, and a Unix …

#DarkSeoul #Wiper #Hastati
2013-01-03 • Trend Micro

Trend Micro’s HeartBeat research describes a targeted campaign that had pursued South Korean government-related organizations and communities since at least 2009. Identified victims included a national policy research institute, a branch of the South Kore…

#HEARTBEAT