Status as of June 26, 2024
Status as of June 26, 2024 Hash 1022f0d39d7ffe88236974b8c0923ecc3 2dd152628fccca62c7b7e479cc4bc5e20 37b07679e0fa36a941daba7693b7559c2 URL 1http[:]fmktrk[.]live/ 2http[:]wecan[.]hasthe[.]technology/upload 3http[:]infraniumproperties[.]com/ IP...
Status as of June 26, 2024
Status as of June 26, 2024 Hash 1022f0d39d7ffe88236974b8c0923ecc3 2dd152628fccca62c7b7e479cc4bc5e20 37b07679e0fa36a941daba7693b7559c2 URL 1http[:]fmktrk[.]live/ 2http[:]wecan[.]hasthe[.]technology/upload 3http[:]infraniumproperties[.]com/ IP...
Kimsuky Group’s New Backdoor (HappyDoor)
Table of Contents Overview Distribution Method and Changes Distribution Method Changes of HappyDoor Detailed Analysis Summary Characteristics Registry Data Packet Data Packet Structure and Server Operation Method Features Information Theft Backdoor Conclusion This report is a summarized version of “Analysis Report of Kimsuky Group’s HappyDoor Malware” introduced in AhnLab Threat
Apple Product Family June 2024 First Security Notice
Overview Apple(https://apple.com) has released a security update that fixes vulnerabilities in products it has...
Weekly Detection Rule (YARA and Snort) Information – Week 4, June 2024
The following is the information on Yara and Snort rules (week 4, June 2024) collected and shared by the AhnLab TIP service. 8 YARA Rules Detection name Description Source malware_cobaltstrike_workersdevloader Detects a CobaltStrike loader https://github.com/JPCERTCC/jpcert-yara Kimsuky_downloader_vbs Detects Kimsuky VBS file downloader Powershell https://github.com/JPCERTCC/jpcert-yara Kimsuky_PokDoc_ps1 Detects Kimsuky device information collection Powershell

