PULSE NAME
DragonOK Backdoor Malware Deployed Against Japanese Targets
WHITE AlienVault 2015-04-20 Modified: 2017-08-24
21
IOCs
MEDIUM VOLUME
This campaign involved five separate phishing attacks, each carrying a different variant of Sysget malware, also known as HelloBridge. The malware was included as an attachment intended to trick the user into opening the malware. This included altering the icon of the executable to appear as other file types as well as decoy documents to trick users into thinking they had opened a legitimate file.
Indicators of Compromise (5 / 21 total)
All FileHash-SHA256 domain URL hostname FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 fc1a8359e0f4cb8d60920dc066b8b21c 2017-08-24
FileHash-MD5 01234567890123456789012345678901 2017-08-24
FileHash-MD5 aa8ac5ed26b9bf4f8d3bd1b2dcaa82f6 2017-08-24
FileHash-MD5 07660815420f6d5b2dcc0f63434a6c60 2017-08-24
FileHash-MD5 4890c2d546fa48a536b75b48b17de023 2017-08-24