KimJongRAT/stealer malware analysis
2013-06-10 • Malwarelu •
https://malware.lu/assets/files/articles/RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf
Attachments
Malware.lu CERT and itrust analyzed a suspicious PDF named “Draft response letter Slovenia.pdf” that they identify as KimJongRAT/Stealer after it was uploaded to malwr.com in May 2013. The document describes a PDF exploit that deploys sysninit.ocx and a launcher, with sections covering resource manipulation, file creation, .lnk persistence, display of a decoy PDF, and hidden initialization. The analysis also documents DLL injection into explorer.exe, an IAT hook of ntdll.ZwQueryDirectoryFile to hide files from Explorer, obfuscation, and VirtualBox detection. Command-and-control behavior is covered through first and second C&C sections, including a Gmail request creation figure, making the report useful for understanding early RAT deployment, stealth, and communications tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 848d0c4c4f608fdd50735a2f0c41af9… | 2013-06-10 | 2013-06-10 |
| HASH | 7ce9d51d51272ae6400249a4a6156fb… | 2013-06-10 | 2013-06-10 |
| HASH | 86964f449a82b8485feef8a5339d0615 | 2013-06-10 | 2013-06-10 |
| HASH | 41d7b66062825d41726bb243075f2a0… | 2013-06-10 | 2013-06-10 |
| HASH | 1ecd67e8690a3f27d282246edc75704… | 2013-06-10 | 2013-06-10 |
| [email protected] | 2013-06-10 | 2013-06-10 | |
| URL | http://www.jhj.wv4.org/test2/se… | 2013-06-10 | 2013-06-10 |
| URL | http://www.test1.wv4.org/ | 2013-06-10 | 2013-06-10 |
| URL | http://www.jhj.wv4.org/test1/ | 2013-06-10 | 2013-06-10 |
| URL | http://www.jhj.wv4.org/test2/ | 2013-06-10 | 2013-06-10 |