Wiper Malware Threat Analysis

2013-03-21 Secure Works

https://www.secureworks.com/research/wiper-malware-analysis-attacking-korean-financial-sector

Dell SecureWorks analyzed destructive Wiper malware used in the March 20, 2013 attacks that disrupted South Korean broadcasters, banks, and other financial-sector systems. The dropper extracted Windows wiper components, PuTTY SSH/SCP binaries, and a Unix Bash wiper script, then searched stored mRemote or SecureCRT sessions for root SSH credentials to copy and execute the Unix wiper on reachable servers. The Windows wipers overwrote MBR, VBR, logical drives, and files using sample-specific strings such as PRINCPES, HASTATI, and PR!NCPES, with one variant waiting until 14:00 KST on the attack date. The report lists hashes for the dropper, wipers, and dropped tools, notes checks for AhnLab-related artifacts, and emphasizes that the samples lacked C2, backdoor, or data-theft functionality while still causing large-scale destructive impact.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 422c767682bee719d85298554af5c59… 2013-03-21 2020-03-09
HASH 510f83af3c41f9892040a8a80b4f3a4… 2013-03-20 2020-03-09
HASH d7a71f83d576fdf75e7978539bac04a… 2013-03-20 2020-03-09
HASH 239ed753232d3cc0e75323d16d35915… 2013-03-20 2020-03-09
HASH bd997996da77811f87c5fd8eeef1f61… 2013-03-21 2013-04-02
HASH 969b970de885b0cfc22d40c08dbf57a… 2013-03-21 2013-04-02
HASH 6f2fb4151f26ff8b735c197da614328… 2013-03-21 2013-04-02
DOMAIN stratigossecurity.com 2013-03-21 2013-03-21
IPv4 101.106.25.105 2013-03-21 2013-03-21

Related Actors

Related Reports

« Back