DPRK Malware Targeting Security Researchers – One Night in Norfolk
Tags
attack-pattern: | Direct Domains - T1583.001 Domains - T1584.001 Malware - T1587.001 Malware - T1588.001 Powershell - T1059.001 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 3ea95d8d-9f2c-441c-9467-214e955e80a7 |
Fingerprint | bdae3ddd68fb85b8 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Jan. 26, 2021, 5:44 a.m. |
Added to db | Sept. 26, 2022, 9:30 a.m. |
Last updated | Nov. 12, 2024, 11:50 a.m. |
Headline | DPRK Malware Targeting Security Researchers |
Title | DPRK Malware Targeting Security Researchers – One Night in Norfolk |
Detected Hints/Tags/Attributes | 28/1/15 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://norfolkinfosec.com/dprk-malware-targeting-security-researchers/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 440 | ✔ | One Night in Norfolk | https://norfolkinfosec.com/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 4 | codevexillium.org |
|
Details | Domain | 7 | www.dronerc.it |
|
Details | Domain | 3 | transplugin.io |
|
Details | File | 1 | vmnat-update.bin |
|
Details | File | 119 | avp.exe |
|
Details | File | 41 | avastui.exe |
|
Details | File | 9 | download.asp |
|
Details | File | 97 | upload.php |
|
Details | File | 7 | upload.asp |
|
Details | md5 | 2 | 56018500f73e3f6cf179d3b853c27912 |
|
Details | md5 | 2 | f5475608c0126582081e29927424f338 |
|
Details | sha1 | 1 | a3060a3efb9ac3da444ef8abc99143293076fe32 |
|
Details | sha1 | 1 | 8e88fd82378794a17a4211fbf2ee2506b9636b02 |
|
Details | sha256 | 2 | 4c3499f3cc4a4fdc7e67417e055891c78540282dccc57e37a01167dfe351b244 |
|
Details | sha256 | 2 | a75886b016d84c3eaacaf01a3c61e04953a7a3adf38acf77a4a2e3a8f544f855 |