Jump to content

NOD

Members
  • Posts

    44
  • Joined

  • Last visited

Posts posted by NOD

  1. 6 hours ago, itman said:

    For the hash given, what VirusTotal is detecting is the malicious .exe version as noted here: https://www.virustotal.com/en/file/8210ff8bf51fa99bf5feac2e5fa5c682b63ba6b963203f39467778beaec12094/analysis/

    BTW - Eset does not detect the .exe.

    Question is if any of the VT vendors listed would have detected the script version of the malware.

    FYI - I have long ago created a HIPS rule to monitor cmd.exe execution.

    Thank you.
    I added the HISP rule right now.:)

  2. 5 hours ago, itman said:

    Good information, thank you.

    And the above video was removed by the developer, but I have a video.
    I will send if necessary.

  3. 1 hour ago, itman said:

    I wouldn't be concerned about this malware unless you reside in South Korea. It's a targeted attack by North Korea against South Korean interests. Also MW Word, etc. only supports the 1997 ver. of HWP attachments. Any newer vers. of HWP are not supported:

    Note: Microsoft Office, OpenOffice, and LibreOffice can open HWP files only if they were created with Hangul '97 - newer versions of the .HWP file cannot be opened with these applications.

    Ref.: https://www.lifewire.com/hwp-file-2621713

    I agree.
    This malicious code is a malicious code to attack Korea. However, ESET is a global group. ESET is doing business in Korea. If so, HWP malware should be analyzed and detected.

    And Korea is using Hangul products in addition to MS Office. So HWP file protection is required. If you do not protect it, Koreans will not use ESET products. I want ESET to be the most famous antivirus product in Korea. So this is to write this article.

×
×
  • Create New...