全球加密货币公司的梦魇:揭秘APT组织“危险密码”
2020-01-08 • Qianxin • The nightmare of global cryptocurrency companies: revealing the "dangerous password" of APT organizations •
ThreatBook reported a cluster it named DangerousPassword after finding compressed trojan packages built around cryptocurrency-themed lures such as monthly business reports, job descriptions, project risk briefs, and salary guidance. The activity targeted cryptocurrency companies and used phishing emails to deliver archive files containing encrypted Office decoys plus malicious LNK files disguised as password text files. When opened, the LNK chain retrieved VBScript through bit.ly redirects and attacker infrastructure, displayed the decoy password to the victim, established startup persistence, checked for Chinese antivirus processes, and sent host and process data to C2. Reported infrastructure included 41.85.145.164:8080, showprice.xyz, start.showprice.xyz, drivegoogle.publicvm.com, and more than 100 lookalike domains impersonating Google, Microsoft, Amazon, and related services. The campaign matters because it shows a focused, multilingual social-engineering operation against cryptocurrency businesses with backdoor execution, reconnaissance, persistence, and potential follow-on remote-control tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | docs.goglesheet.com | 2020-01-08 | 2022-01-13 |
| DOMAIN | drivegoogle.publicvm.com | 2019-07-09 | 2021-05-24 |
| IPv4 | 41.85.145.164 | 2020-01-08 | 2021-01-28 |
| HASH | a50ec2f42bec1c43e952de2728de021… | 2020-01-08 | 2020-08-18 |
| DOMAIN | download.showprice.xyz | 2019-07-09 | 2020-08-18 |
| DOMAIN | msupdate.publicvm.com | 2020-01-08 | 2020-06-24 |
| DOMAIN | start.showprice.xyz | 2019-07-09 | 2020-05-06 |
| URL | http://download.showprice.xyz:8… | 2020-01-08 | 2020-01-08 |
| URL | http://start.showprice.xyz:8080… | 2020-01-08 | 2020-01-08 |