본문 바로가기

Analysis

13. 분석 특징 정리

분석 특징 정리 글(지속적 업데이트 예정, 그룹 별)

 

Lazarus

- XOR 키 값

1. 0x39 0xC3 0xB2 0x70 0x05 0x85 0x3E 0x98 0x66 0x1C 0x8B 0xBC 0x1B 0xDD 0xEA 0xF8
2. 0xAA

- URL

1.

https://www[.]sparkdept[.]com/wp-content/uploads/themify/theme2.db.enc

https://www[.]sparkdept[.]com/wp-content/uploads/themify/theme4.db.enc 

2. https://stokeinvestor[.]com/common[.]php 
https://growthincone[.]com/board[.]php
https://inverstingpurpose[.]com/head[.]php


Nemty ransomware

- URL

http://api[.]db-ip[.]com/v2/(IP address)/countryName

http://api[.]ipify[.]org

https://pbs[.]twing[.]com/media/Dn4vwaRWDAY-tUu.jpg

 

 

- Except Encryption

$RECYCLE.BIN  rsa NTDETECT.COM ntldr MSDOS.SYS IO.SYS boot.ini AUTOEXEC.BAT 
ntuser.dat desktop.ini CONFIG.SYS RECYCLER BOOTSECT.BAK bootmgr programdata 
appdata windows DECRYPT.txt 

암호화 제외 확장자
nemty log LOG CAB cab CMD cmd COM com cpl CPL exe EXE ini INI 
dll DLL lnk LNK url URL ttf TTF
반응형