KimJongRAT/stealer malware analysis

2013-06-10 Malwarelu

https://malware.lu/assets/files/articles/RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf

Attachments

RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf (2 MB)

Thumbnail for KimJongRAT/stealer malware analysis

Malware.lu CERT and itrust analyzed a suspicious PDF named “Draft response letter Slovenia.pdf” that they identify as KimJongRAT/Stealer after it was uploaded to malwr.com in May 2013. The document describes a PDF exploit that deploys sysninit.ocx and a launcher, with sections covering resource manipulation, file creation, .lnk persistence, display of a decoy PDF, and hidden initialization. The analysis also documents DLL injection into explorer.exe, an IAT hook of ntdll.ZwQueryDirectoryFile to hide files from Explorer, obfuscation, and VirtualBox detection. Command-and-control behavior is covered through first and second C&C sections, including a Gmail request creation figure, making the report useful for understanding early RAT deployment, stealth, and communications tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 848d0c4c4f608fdd50735a2f0c41af9… 2013-06-10 2013-06-10
HASH 7ce9d51d51272ae6400249a4a6156fb… 2013-06-10 2013-06-10
HASH 86964f449a82b8485feef8a5339d0615 2013-06-10 2013-06-10
HASH 41d7b66062825d41726bb243075f2a0… 2013-06-10 2013-06-10
HASH 1ecd67e8690a3f27d282246edc75704… 2013-06-10 2013-06-10
EMAIL [email protected] 2013-06-10 2013-06-10
URL http://www.jhj.wv4.org/test2/se… 2013-06-10 2013-06-10
URL http://www.test1.wv4.org/ 2013-06-10 2013-06-10
URL http://www.jhj.wv4.org/test1/ 2013-06-10 2013-06-10
URL http://www.jhj.wv4.org/test2/ 2013-06-10 2013-06-10

Related Reports

« Back