Hi folks,
attached are samples of a malware with alleged purpose to steal sensitive information from South Korea / U.S. military.
Abstract of strings:
https://www.virustotal.com/en/file/1f04 ... /analysis/ (Dropper)
https://www.virustotal.com/en/file/2d8b ... /analysis/ (Dropper)
https://www.virustotal.com/en/file/4df7 ... /analysis/ (Payload)
https://www.virustotal.com/en/file/020c ... /analysis/ (Payload)
attached are samples of a malware with alleged purpose to steal sensitive information from South Korea / U.S. military.
Abstract of strings:
Code: Select all
Samples:Military
military
MILITARY
weapon
Weapon
WEAPON
battle
Battle
BATTLE
munition
missile
Missile
MISSILE
Aircraft
Figther
Resolve
resolve
Operation
operation
OPERATION
Air Force
AirForce
airforce
AF Portal
AFPortal
EMAIL
AIRFORCE
AIR FORCE
email
KORCOM
CENTRIX
KR/FE
Intranet
intranet
TNOSC
COMSEC
PACCOM
PENTAGON
cassifi
securet
CASSIFI
Cassifi
Certificat
CERTIFICAT
Pentagon
pentagon
https://www.virustotal.com/en/file/1f04 ... /analysis/ (Dropper)
https://www.virustotal.com/en/file/2d8b ... /analysis/ (Dropper)
https://www.virustotal.com/en/file/4df7 ... /analysis/ (Payload)
https://www.virustotal.com/en/file/020c ... /analysis/ (Payload)
Attachments
PW: infected
(1.08 MiB) Downloaded 93 times
(1.08 MiB) Downloaded 93 times
Malware Reversing
http://www.malware-reversing.com
http://www.malware-reversing.com