« Reports in 2014 »

19 reports

2014-12-19 • USCISA

US-CERT reports destructive malware activity against a major entertainment company using an SMB worm tool with multiple components for propagation, access, proxying, and wiping. The worm brute-forces Windows SMB shares on port 445, copies itself to reacha…

#Blockbuster #Destover #WIPALL
2014-12-17 • Cisco Talos

Cisco Talos analyzed a wiper malware variant to improve network detection for beaconing behavior from the disk-wiping component. The team examined related samples, modified hard-coded command-and-control addresses to a local decoy environment, and shorten…

#Destover #WIPALL
2014-05-07 • ESTSecurity

ALYac analyzed a malicious HWP document judged to resemble previously reported Kimsuky-style activity targeting Korean organizations. The document abuses a Hancom Office vulnerability through hidden HWP sections with abnormally large paragraph text data, …

#Kimsuky #Hangul