Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Operation HARKONNEN - German Speaking #13

Closed
chrisddom opened this issue Sep 6, 2014 · 11 comments
Closed

Operation HARKONNEN - German Speaking #13

chrisddom opened this issue Sep 6, 2014 · 11 comments
Labels

Comments

@chrisddom
Copy link

Might be worth adding-

http://cybertinel.com/wp-content/uploads/2014/09/HARKONNEN-OPERATION-CYBER-ESPIONAGE.pdf

@GelosSnake
Copy link

really? have you read this report?

@the-shelter
Copy link

It’s like a sale pitch. Couldn’t find any other reports getting deeper in a quick google search

@GelosSnake
Copy link

Google for Win7.Generic (:

@chrisddom
Copy link
Author

I skipped the sales guff, saw the description of a long targeted campaign that I saw had been previously tagged as crimeware and thought - ah that tends to be interesting.
But looking at the domains eg; http://totalhash.com/search/dnsrr:download-web-shield.com
yeah... that really does look like crimeware a sales guy has written up as something very different.

@chrisddom
Copy link
Author

And I don't know how $150k comes from a few domains and ssl certs :)

@kbandla
Copy link
Owner

kbandla commented Sep 6, 2014

This has been in various .il news past week. The only metadata/IOCs I found are here, like chris pointed
Yeah looks salesy overall. I'll keep an eye open for any hashes.

@the-shelter
Copy link

I saw that one. I was hoping to find some deeper analysing document. So far nothing found

@chrisddom
Copy link
Author

Lots of samples available in german installers for freeware packed with typical adware https://malwr.com/analysis/ZGY4MGNjZDQ1NjZjNGQ4MTk2ZGZhYTg4Zjk4ODBjYTA/

@the-shelter
Copy link

I did found those. I was interested in the background of the operation (Harkonnen).

@kbandla
Copy link
Owner

kbandla commented Sep 8, 2014

Dynamoo has some analysis on the same malware. This shows that it is adware, and not apt.
After collecting info and asking around, this report seems is a little too fantastic. Skipping this report. Thanks for the discussion!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants