13.05.2016 Views

THE HISTORY OF THE DARKSEOUL GROUP AND THE SONY INTRUSION MALWARE DESTOVER

001398694

001398694

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ule DarkSeoul_Obf_Caracachs : Backdoor<br />

{<br />

meta:<br />

author = "Blue Coat Systems, Inc."<br />

info = "Obfuscation method used by the DarkSeoul group"<br />

strings:<br />

$a1={F3EEAEFFFBB821BF9AE3D820FDC0}<br />

condition:<br />

any of them<br />

}<br />

rule DarkSeoul_Keystrings : Backdoor<br />

{<br />

meta:<br />

author = "Blue Coat Systems, Inc."<br />

info = "Encryption keys used by the DarkSeoul group"<br />

strings:<br />

$a1 = "Bb102@jH4$t3hg%6&G1s*2J3gCNwVr*UeI!Dr3hytg^CHGf%ion"<br />

$a2 = "BAISEO%$2fas9vQsfvx%$"<br />

$a3 = "A39405WKELsdfirpsdLDPskDORkbLRTP12330@3$223%!"<br />

condition:<br />

any of them<br />

}<br />

rule Joanap :<br />

{<br />

meta:<br />

}<br />

author = "Blue Coat Systems, Inc."<br />

info = "SMB worm family used by the DarkSeoul group"<br />

strings:<br />

$a1="NTLMSSP"<br />

$a2="MiniDumpWriteDump"<br />

$a3="password

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!