Brambul

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search
Brambul
Malware details
Technical name
TypeComputer worm
AuthorsLazarus
Technical details
PlatformWindows XP
Written inKorean

Brambul is an SMB protocol computer worm that decrypts[clarification needed] and automatically moves from one computer to its second computer.

It is responsible for the dropping of the Joanap botnet.

History

[edit | edit source]

Brambul was first discovered in 2009 and has not had a disclosure prior to its notoriety. It was observed by cybersecurity firms and was not extensive subject.[4]

Sony hack (Late 2014)

[edit | edit source]

Brambul was among the malware to be identified during the Sony Pictures hack.

Investigation (Early 2019)

[edit | edit source]

Brambul as well as Joanap botnet have both been shut down via a court order.

Cycle

[edit | edit source]

The computer worm has the ability to automatically scan IP addresses and decrypt passwords including, but not limited to the following.[1]

Password Description
password The word password
!@#$% 1-5 typed with the shift key
!@#$%^&*() all ten number keys typed with the shift key
~!@#$%^&*()_+ the entire top row of keys typed with the shift key

System drive share

[edit | edit source]

Brambul will share information of the system to the cyberattacker. Information shared includes the IP address, hostname and the username and password.[5]

References

[edit | edit source]
  1. ^ a b Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
  2. ^ Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
  3. ^ Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
  4. ^ Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
  5. ^ Lua error in Module:Citation/CS1/Configuration at line 2172: attempt to index field '?' (a nil value).
[edit | edit source]