Makop Ransomware Disguised as Resume Being Distributed in Korea - ASEC BLOG
Tags
attack-pattern: | Malicious File - T1204.002 Malware - T1587.001 Malware - T1588.001 |
Common Information
Type | Value |
---|---|
UUID | 918570a2-6f23-4625-aa5f-92da1a0dd05a |
Fingerprint | a710f87909f59676 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Oct. 13, 2021, 10:30 a.m. |
Added to db | Sept. 11, 2022, 4:59 p.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | Makop Ransomware Disguised as Resume Being Distributed in Korea |
Title | Makop Ransomware Disguised as Resume Being Distributed in Korea - ASEC BLOG |
Detected Hints/Tags/Attributes | 25/1/49 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/en/27256/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 38 | ntdetect.com |
|
Details | Domain | 16 | goat.si |
|
Details | 1 | characters].[baseus0906@goat.si |
||
Details | File | 46 | msftesql.exe |
|
Details | File | 58 | sqlagent.exe |
|
Details | File | 62 | sqlbrowser.exe |
|
Details | File | 119 | sqlservr.exe |
|
Details | File | 66 | sqlwriter.exe |
|
Details | File | 67 | oracle.exe |
|
Details | File | 57 | ocssd.exe |
|
Details | File | 61 | dbsnmp.exe |
|
Details | File | 57 | synctime.exe |
|
Details | File | 2 | agntsrvc.exe |
|
Details | File | 57 | mydesktopqos.exe |
|
Details | File | 54 | isqlplussvc.exe |
|
Details | File | 56 | xfssvccon.exe |
|
Details | File | 60 | mydesktopservice.exe |
|
Details | File | 57 | ocautoupds.exe |
|
Details | File | 57 | encsvc.exe |
|
Details | File | 41 | firefoxconfig.exe |
|
Details | File | 55 | tbirdconfig.exe |
|
Details | File | 57 | ocomm.exe |
|
Details | File | 57 | mysqld.exe |
|
Details | File | 43 | mysqld-nt.exe |
|
Details | File | 40 | mysqld-opt.exe |
|
Details | File | 58 | dbeng50.exe |
|
Details | File | 55 | sqbcoreservice.exe |
|
Details | File | 199 | excel.exe |
|
Details | File | 52 | infopath.exe |
|
Details | File | 91 | msaccess.exe |
|
Details | File | 102 | mspub.exe |
|
Details | File | 74 | onenote.exe |
|
Details | File | 173 | outlook.exe |
|
Details | File | 92 | powerpnt.exe |
|
Details | File | 99 | steam.exe |
|
Details | File | 58 | thebat.exe |
|
Details | File | 35 | thebat64.exe |
|
Details | File | 63 | thunderbird.exe |
|
Details | File | 86 | visio.exe |
|
Details | File | 323 | winword.exe |
|
Details | File | 90 | wordpad.exe |
|
Details | File | 120 | boot.ini |
|
Details | File | 90 | bootfont.bin |
|
Details | File | 38 | io.sys |
|
Details | File | 4 | readme-warning.txt |
|
Details | File | 196 | desktop.ini |
|
Details | File | 2 | makop.c4 |
|
Details | md5 | 1 | 3d044acc234d0c4532e6a7eb694b8608 |
|
Details | md5 | 1 | 996872f7782f5507e757c88f2b14bc13 |