Summary:
Researchers disclosed crucial information regarding an RTF file believed to be utilized by the notorious hacking group Sharp Panda. The file was uploaded to a New Zealand server by an unidentified and unregistered user via a web interface. What makes this discovery particularly intriguing is that the content within the decoy document was written in Japanese, leading to the assumption that the potential victim either resides in Japan or is proficient in the Japanese language.[/subscribe_to_unlock_form]
Summary:
Researchers disclosed crucial information regarding an RTF file believed to be utilized by the notorious hacking group Sharp Panda. The file was uploaded to a New Zealand server by an unidentified and unregistered user via a web interface. What makes this discovery particularly intriguing is that the content within the decoy document was written in Japanese, leading to the assumption that the potential victim either resides in Japan or is proficient in the Japanese language.[emaillocker id="1283"]
The RTF file, upon execution, initiates a series of actions, dropping a tc51.t downloader and subsequently running it through a Windows Update task with the command: “rundll32.exe %Temp%\tc51.t StartA”. In the course of analysis, researchers uncovered a significant lead in the form of a PDB (Program Database) path: “D:\Project\Downloader\dll_rls\Downloader.pdb”. Furthermore, they identified the RC4 key associated with the attack as "86nb3ecw."
Despite these findings, the payload that was intended to be delivered by the attack remained inaccessible to the analysts. The specific nature of this payload raises further questions and emphasizes the need for continued investigation into Sharp Panda's activities, especially as they appear to target Japanese-speaking individuals or entities, as indicated by the Japanese language used in the decoy document.
Threat Profile:

References:
Eventus Security Threat Research & Development Team
[/emaillocker]