Analysis Report on Malware  Distributed Through a South  Korean Language Academy  Website

Analysis Report on Malware Distributed Through a South Korean Language Academy Website

Overview   The AhnLab SEcurity intelligence Center (ASEC) recently confirmed that a Meterpreter backdoor, port forwarding, and IIS module malware tools were installed through an improperly managed Windows IIS (Internet Information Services) web server. In the case of this attack, the threat actor ultimately installed IIS module malware on the