Case of Malware Distribution Linking to Illegal Gambling Website Targeting Korean Web Server
ID: eb9d149b-df83-5be9-b1c2-1e10b6018fef
STIX ID: report--eb9d149b-df83-5be9-b1c2-1e10b6018fef
Feed Name: ASEC
AhnLab ASEC discovered an active campaign compromising poorly secured Windows IIS web servers in South Korea: attackers executed reconnaissance commands, installed a Meterpreter backdoor and HTran port-forwarder, created a persistent user account, deployed an IIS module that detects search-engine requests and injects JavaScript redirects to illegal gambling sites, and used ProcDump to dump lsass.exe to harvest credentials. The report includes file detections, MD5 hashes, malicious URLs, and an attacker IP, and warns that the injected response script could be changed to perform other malicious actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
