IoC (TT Malware Log)

Malware の IoC(Indicator)情報

◆注意◆ マルウェア解析専析家向けサイト

     FQDN, URL,IPアドレス等はそのまま掲載しています


** Caution ** Malware expert site

                    FQDN, URL, IP address etc. are posted as they are

韓国 サイバーテロ

【インディケータ情報】

■マルウェア情報(ApcRunCmd.exe)

MD5 db4bbdc36a78a8807ad9b15a562515c4
SHA1 309af225ac59e1d2ffaada11e09f5715bce16c1e
SHA256 d7a71f83d576fdf75e7978539bac04ad8b6605207b29379b89c24c0d0f31da61
SHA512
SSDEEP 192:0v5uXGwnkGjGlCdhAtNvIQszEtTmhVYWY02noM1qtT57MkJRVtyycpc7numoZ9:E5uXGw/ClCTEZ3WNDMEN5yycpcrumoZ
authentihash 8aa11954d8f4b60de8febe0cc685da5406c52b4b451ab43ab2fdf416afa26167
imphash 8cf2375491e257d65da71e5d263d7df7
File Size 24576 bytes
File Type PE32 executable for MS Windows (GUI) Intel 80386 32-bit
コンパイル日時 2013-01-31 10:27:18
Debug Path
File Name ApcRunCmd.exe
File Path
生成ファイル
特徴
参考情報 https://www.virustotal.com/ja/file/d7a71f83d576fdf75e7978539bac04ad8b6605207b29379b89c24c0d0f31da61/analysis/

■マルウェア情報(ApcRunCmd.exe)

MD5 f0e045210e3258dad91d7b6b4d64e7f3
SHA1 4079b6212a5398b6912a37f27a8c39ca3a7f8585
SHA256 929dc09a8bd8491b77f050a2736d39c30597ec7090d8f081eeb6179b6f8ab033
SHA512
SSDEEP 384:e5uXGw/ClCTEZ3WDcXDMEN5yyqbpcrumoZ:UsD/Cl6E9UcXy/pCumo
authentihash 60ba5186e575ea4b8847e30a21d7051642e297d8a3cb63a5900ee92415788f21
imphash
File Size 24576 bytes
File Type PE32 executable for MS Windows (GUI) Intel 80386 32-bit
コンパイル日時 2013-01-31 10:27:18
Debug Path
File Name ApcRunCmd.exe
File Path
生成ファイル
特徴
参考情報 https://www.virustotal.com/ja/file/929dc09a8bd8491b77f050a2736d39c30597ec7090d8f081eeb6179b6f8ab033/analysis/

OthDown.exe
MD5: 5fcd6e1dace6b0599429d913850f0364
VirusTotal: https://www.virustotal.com/ja/file/239ed753232d3cc0e75323d16d359150937934d30da022628e575997c8dd60a2/analysis/
mb_join.exe
MD5: 0A8032CD6B4A710B1771A080FA09FB87

imbc.exe
sbs.exe
kbs.exe
Bull.exe
Sun.exe
asd.exe
38.exe
39.exe
Sad.exe
down.exe
v3lite.exe
APCRunCmd.DRP
MD5: 9263E40D9823AECF9388B64DE34EAE54
VirusTotal: https://www.virustotal.com/ja/file/422c767682bee719d85298554af5c59cf7e48cf57daaf1c5bdd87c5d1aab40cc/analysis/