IoC (TT Malware Log)

Malware の IoC(Indicator)情報

◆注意◆ マルウェア解析専析家向けサイト

     FQDN, URL,IPアドレス等はそのまま掲載しています


** Caution ** Malware expert site

                    FQDN, URL, IP address etc. are posted as they are

Daserf(Visual C)

【インディケータ情報】

■ハッシュ情報(Sha256) - Daserf(Visual C) -

21111136d523970e27833dd2db15d7c50803d8f6f4f377d4d9602ba9fbd355cd
15abe7b1355cd35375de6dde57608f6d3481755fdc9e71d2bfc7c7288db4cd92
2bdb88fa24cffba240b60416835189c76a9920b6c3f6e09c3c4b171c2f57031c
85544d2bcaf8e6ca32bbc0a9e9583c9db1dce837043f555a7ff66363d5858439
f8f31f73157bf049b318429c1d60ad7ff2851e62535d95cf8d121216b95c8602
b1690facbce9bcc66ebf18f138dbbc10c3662a2034c211e0c414e47c7e208b4a
e620c9d19d7d1f609e0bb08465e4c58db97fd0158fb286d938542fc1f03a2302
2dc24622c1e91642a21a64c0dd31cbe953e8f77bd3d6abcf2c4676c3b11bb162
a4afd9df1b4cc014c3a89d7b4a560fa3e368b02286c42841762714b23e68cc05
dab557bae0eb93475c2c2639f186fd717dd57d8d6354232838f44ba6b6a07172
db6a6a4f675cba87405c9c7b016713d3e65b052ffc6c8963764a3d3788f432fa
4b8ca82e6f407792cfb51de881f06b86bd4b59f85746b29c3287aee0015b1683
db8b494de8d897976288c8ccee707ff7b7967fb48caef99d75687584191c2411
e2fd17445d81df89f7a9c1ff1c69c9b382215f597db5e4730f5c76557a6fd1f9
0a031665d05e82038d620facf9d4a86a89e78544f2f770f579c980dae2e252bf
fa9a3341649e798bbc340ce9b2fe69791fe733aa9e46da666ce13b8cf7ca8f4d
f06b440052bd2c2eb127c33c35a80c4eca34a06360d3ee1bb37348d6029dc955
2a39372dea901665ab9429d2f15b3f4fb10706423e177226539047ee1ac3e4a3

(以上は SecureWorks(Dell) の情報: 引用元は https://www.secureworks.com/research/bronze-butler-targets-japanese-businesses )


【検索】

google: 21111136d523970e27833dd2db15d7c50803d8f6f4f377d4d9602ba9fbd355cd
google: 15abe7b1355cd35375de6dde57608f6d3481755fdc9e71d2bfc7c7288db4cd92
google: 2bdb88fa24cffba240b60416835189c76a9920b6c3f6e09c3c4b171c2f57031c
google: 85544d2bcaf8e6ca32bbc0a9e9583c9db1dce837043f555a7ff66363d5858439
google: f8f31f73157bf049b318429c1d60ad7ff2851e62535d95cf8d121216b95c8602
google: b1690facbce9bcc66ebf18f138dbbc10c3662a2034c211e0c414e47c7e208b4a
google: e620c9d19d7d1f609e0bb08465e4c58db97fd0158fb286d938542fc1f03a2302
google: 2dc24622c1e91642a21a64c0dd31cbe953e8f77bd3d6abcf2c4676c3b11bb162
google: a4afd9df1b4cc014c3a89d7b4a560fa3e368b02286c42841762714b23e68cc05
google: dab557bae0eb93475c2c2639f186fd717dd57d8d6354232838f44ba6b6a07172
google: db6a6a4f675cba87405c9c7b016713d3e65b052ffc6c8963764a3d3788f432fa
google: 4b8ca82e6f407792cfb51de881f06b86bd4b59f85746b29c3287aee0015b1683
google: db8b494de8d897976288c8ccee707ff7b7967fb48caef99d75687584191c2411
google: e2fd17445d81df89f7a9c1ff1c69c9b382215f597db5e4730f5c76557a6fd1f9
google: 0a031665d05e82038d620facf9d4a86a89e78544f2f770f579c980dae2e252bf
google: fa9a3341649e798bbc340ce9b2fe69791fe733aa9e46da666ce13b8cf7ca8f4d
google: f06b440052bd2c2eb127c33c35a80c4eca34a06360d3ee1bb37348d6029dc955
google: 2a39372dea901665ab9429d2f15b3f4fb10706423e177226539047ee1ac3e4a3


【VT検索】

https://www.virustotal.com/gui/file/21111136d523970e27833dd2db15d7c50803d8f6f4f377d4d9602ba9fbd355cd
https://www.virustotal.com/gui/file/15abe7b1355cd35375de6dde57608f6d3481755fdc9e71d2bfc7c7288db4cd92
https://www.virustotal.com/gui/file/2bdb88fa24cffba240b60416835189c76a9920b6c3f6e09c3c4b171c2f57031c
https://www.virustotal.com/gui/file/85544d2bcaf8e6ca32bbc0a9e9583c9db1dce837043f555a7ff66363d5858439
https://www.virustotal.com/gui/file/f8f31f73157bf049b318429c1d60ad7ff2851e62535d95cf8d121216b95c8602
https://www.virustotal.com/gui/file/b1690facbce9bcc66ebf18f138dbbc10c3662a2034c211e0c414e47c7e208b4a
https://www.virustotal.com/gui/file/e620c9d19d7d1f609e0bb08465e4c58db97fd0158fb286d938542fc1f03a2302
https://www.virustotal.com/gui/file/2dc24622c1e91642a21a64c0dd31cbe953e8f77bd3d6abcf2c4676c3b11bb162
https://www.virustotal.com/gui/file/a4afd9df1b4cc014c3a89d7b4a560fa3e368b02286c42841762714b23e68cc05
https://www.virustotal.com/gui/file/dab557bae0eb93475c2c2639f186fd717dd57d8d6354232838f44ba6b6a07172
https://www.virustotal.com/gui/file/db6a6a4f675cba87405c9c7b016713d3e65b052ffc6c8963764a3d3788f432fa
https://www.virustotal.com/gui/file/4b8ca82e6f407792cfb51de881f06b86bd4b59f85746b29c3287aee0015b1683
https://www.virustotal.com/gui/file/db8b494de8d897976288c8ccee707ff7b7967fb48caef99d75687584191c2411
https://www.virustotal.com/gui/file/e2fd17445d81df89f7a9c1ff1c69c9b382215f597db5e4730f5c76557a6fd1f9
https://www.virustotal.com/gui/file/0a031665d05e82038d620facf9d4a86a89e78544f2f770f579c980dae2e252bf
https://www.virustotal.com/gui/file/fa9a3341649e798bbc340ce9b2fe69791fe733aa9e46da666ce13b8cf7ca8f4d
https://www.virustotal.com/gui/file/f06b440052bd2c2eb127c33c35a80c4eca34a06360d3ee1bb37348d6029dc955
https://www.virustotal.com/gui/file/2a39372dea901665ab9429d2f15b3f4fb10706423e177226539047ee1ac3e4a3






【ブログ】

◆BRONZE BUTLER Targets Japanese Enterprises (SecureWorks, 2017/10/12)
https://www.secureworks.com/research/bronze-butler-targets-japanese-businesses
http://malware-log.hatenablog.com/entry/2017/10/12/000000_6