PULSE NAME
DragonOK Backdoor Malware Deployed Against Japanese Targets
WHITE AlienVault 2015-04-20 Modified: 2017-08-24
21
IOCs
MEDIUM VOLUME
This campaign involved five separate phishing attacks, each carrying a different variant of Sysget malware, also known as HelloBridge. The malware was included as an attachment intended to trick the user into opening the malware. This included altering the icon of the executable to appear as other file types as well as decoy documents to trick users into thinking they had opened a legitimate file.
Indicators of Compromise (2 / 21 total)
All FileHash-SHA256 domain URL hostname FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
URL http://bbs.reweblink.com/index.html 2017-08-24
URL http://https.reweblink.com:443 2017-08-24