Brambul
   HOME

TheInfoList



OR:

Brambul is an SMB protocol
computer worm A computer worm is a standalone malware computer program that replicates itself in order to spread to other computers. It often uses a computer network to spread itself, relying on security failures on the target computer to access it. It will ...
that decrypts and automatically moves from one computer to its second computer. It is responsible for the dropping of the Joanap botnet.


History

Brambul was first discovered in 2009 and has not had a disclosure prior to its notoriety. It was observed by cybersecurity firms and was not extensive subject.


Sony hack (Late 2014)

Brambul was among the malware to be identified during the
Sony Pictures hack On November 24, 2014, the hacker group " Guardians of Peace" leaked confidential data from the film studio Sony Pictures Entertainment (SPE). The data included employee emails, personal and family information, executive salaries, copies of th ...
.


Investigation (Early 2019)

Brambul as well as Joanap botnet have both been shut down via a court order.


Cycle

The computer worm has the ability to automatically scan IP addresses and decrypt passwords including, but not limited to the following.


System drive share

Brambul will share information of the system to the cyberattacker. Information shared includes the
IP address An Internet Protocol address (IP address) is a numerical label such as that is assigned to a device connected to a computer network that uses the Internet Protocol for communication. IP addresses serve two main functions: network interface i ...
, hostname and the username and password.


References


External links


HIDDEN COBRA – Joanap Backdoor Trojan and Brambul Server Message Block Worm , CISA
{{Hacking in the 2010s Computer worms 2014 in computing