Malware Used by APT37

Malware Used by APT37
pull/170/head
eCrimeLabs 2018-03-14 22:11:43 +00:00 committed by GitHub
parent 84215d0003
commit bfeb9d772c
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 56 additions and 1 deletions

View File

@ -3989,11 +3989,66 @@
],
"synonyms": [
"FE_APT_Backdoor_SHUTTERSPEED",
"APT.Backdoor.SHUTTERSPEED",
"APT.Backdoor.SHUTTERSPEED"
]
},
"uuid": "d909efe3-abc3-4be0-9640-e4727542fa2b"
},
{
"value": "SLOWDRIFT",
"description": "SLOWDRIFT is a launcher that communicates via cloud based infrastructure. It sends system information to the attacker command and control and then downloads and executes additional payloads.Lure documents distributing SLOWDRIFT were not tailored for specific victims, suggesting that TEMP.Reaper is attempting to widen its target base across multiple industries and in the private sector. SLOWDRIFT was seen being deployed against academic and strategic targets in South Korea using lure emails with documents leveraging the HWP exploit. Recent SLOWDRIFT samples were uncovered in June 2017 with lure documents pertaining to cyber crime prevention and news stories. These documents were last updated by the same actor who developed KARAE, POORAIM and ZUMKONG.",
"meta": {
"refs": [
"https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf"
],
"synonyms": [
"FE_APT_Downloader_Win_SLOWDRIFT_1",
"FE_APT_Downloader_Win_SLOWDRIFT_2",
"APT.Downloader.SLOWDRIFT"
]
},
"uuid": "e5a9a2ec-348e-4a2f-98dd-16c3e8845576"
},
{
"value": "SOUNDWAVE",
"description": "SOUNDWAVE is a windows based audio capturing utility. Via command line it accepts the -l switch (for listen probably), captures microphone input for 100 minutes, writing the data out to a log file in this format: C:\\Temp\\HncDownload\\YYYYMMDDHHMMSS.log.",
"meta": {
"refs": [
"https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf"
],
"synonyms": [
"FE_APT_HackTool_Win32_SOUNDWAVE_1"
]
},
"uuid": "6a0e3c75-5a59-4747-8fec-2e344a328575"
},
{
"value": "ZUMKONG",
"description": "ZUMKONG is a credential stealer capable of harvesting usernames and passwords stored by Internet Explorer and Chrome browsers. Stolen credentials are emailed to the attacker via HTTP POST requests to mail[.]zmail[.]ru.",
"meta": {
"refs": [
"https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf"
],
"synonyms": [
"FE_APT_Trojan_Zumkong",
"Trojan.APT.Zumkong"
]
},
"uuid": "6f1b9155-5de4-4ef7-9f42-60007599c477"
},
{
"value": "WINERACK",
"description": "WINERACK is backdoor whose primary features include user and host information gathering, process creation and termination, filesystem and registry manipulation, as well as the creation of a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands. Other capabilities include the enumeration of files, directories, services, active windows and processes.",
"meta": {
"refs": [
"https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf"
],
"synonyms": [
"FE_APT_Backdoor_WINERACK",
"Backdoor.APT.WINERACK"
]
},
"uuid": "49025073-4cd3-43b8-b893-e80a1d3adc04"
}
]
}