Elastic catches DPRK passing out KANDYKORN — Elastic Security Labs
Tags
Common Information
Type | Value |
---|---|
UUID | 9dc3d64a-f1f9-4c73-935d-a36518c841b0 |
Fingerprint | b1121c116cb705d7 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Nov. 1, 2023, midnight |
Added to db | Nov. 19, 2023, 6:17 a.m. |
Last updated | Nov. 17, 2024, 7:44 p.m. |
Headline | Elastic catches DPRK passing out KANDYKORN |
Title | Elastic catches DPRK passing out KANDYKORN — Elastic Security Labs |
Detected Hints/Tags/Attributes | 126/3/44 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 163 | ✔ | — | https://media.cert.europa.eu/rss?type=category&id=Malware&language=en&duplicates=false | 2024-08-30 22:08 |
Details | 306 | ✔ | Elastic Security Labs | https://www.elastic.co/security-labs/rss/feed.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 15 | watcher.py |
|
Details | Domain | 11 | testspeed.py |
|
Details | Domain | 9 | bridges.zip |
|
Details | Domain | 88 | main.py |
|
Details | Domain | 3 | tp-globa.xyz |
|
Details | Domain | 359 | com.apple |
|
Details | Domain | 3 | discord.app |
|
Details | Domain | 194 | drive.google.com |
|
Details | Domain | 1 | pesnam.publicvm.com |
|
Details | Domain | 1 | bitscrunnch.linkpc.net |
|
Details | Domain | 1 | jobintro.linkpc.net |
|
Details | Domain | 1 | jobdescription.linkpc.net |
|
Details | Domain | 1 | docsenddata.linkpc.net |
|
Details | Domain | 1 | docsendinfo.linkpc.net |
|
Details | Domain | 1 | datasend.linkpc.net |
|
Details | Domain | 1 | exodus.linkpc.net |
|
Details | Domain | 1 | bitscrunnch.run.place |
|
Details | Domain | 1 | coupang-networks.pics |
|
Details | Domain | 1 | group.pro-tokyo.top |
|
Details | Domain | 4127 | github.com |
|
Details | Domain | 55 | process.name |
|
Details | Domain | 32 | file.name |
|
Details | Domain | 5 | dll.name |
|
Details | Domain | 110 | www.reddit.com |
|
Details | File | 15 | watcher.py |
|
Details | File | 10 | testspeed.py |
|
Details | File | 9 | bridges.zip |
|
Details | File | 76 | main.py |
|
Details | File | 4 | macos.tmp |
|
Details | File | 1 | pesnam.pub |
|
Details | File | 1 | effective_process.exe |
|
Details | File | 49 | process.exe |
|
Details | sha1 | 1 | 5555494485b460f1e2343dffaef9b94d01136320 |
|
Details | sha256 | 3 | 2360a69e5fd7217e977123c81d3dbb60bf4763a9dae6949bc1900234f7762df1 |
|
Details | sha256 | 3 | 3ea2ead8f3cec030906dcbffe3efd5c5d77d5d375d4a54cca03bfe8a6cb59940 |
|
Details | sha256 | 3 | 927b3564c1cf884d2a05e1d7bd24362ce8563a1e9b85be776190ab7f8af192f6 |
|
Details | IPv4 | 5 | 23.254.226.90 |
|
Details | IPv4 | 3 | 192.119.64.43 |
|
Details | Url | 1 | https://drive.google.com/file/d1kw5nq8mzccug6mp4qtkywlt3hizzhnil2 |
|
Details | Url | 1 | https://github.com/prtof |
|
Details | Url | 1 | https://github.com/wokurks |
|
Details | Url | 1 | http://tp-globa.xyz//odhlca1mlup/lz5rzpxwsh/7yzkyqi43s/fp7savdx6c/bfc |
|
Details | Url | 1 | https://www.reddit.com/r/hacking/comments/15b4uti/comment/jtprebt |
|
Details | Url | 1 | https://www.reddit.com/r/pihole/comments/15d11do/malware_project_mimics_pihole/jtzmpqh |