掘金行动(Operation Gold Hunting) - 目标瞄准前沿科技行业 - 安恒威胁情报中心

2020-11-12 安恒信息 Operation Gold Hunting - Targeting cutting-edge technology industries - Anheng Threat Intelligence Center

https://starmap.dbappsecurity.com.cn/blog/articles/2020/11/12/operation-gold-hunting/

Thumbnail for 掘金行动(Operation Gold Hunting) - 目标瞄准前沿科技行业 - 安恒威胁情报中心

DBAPPSecurity’s Operation Gold Hunting report describes phishing documents aimed at venture-capital and frontier-technology targets, using NDA and investment-presentation themes as lures. The analyzed DOCX files used remote template injection to fetch malicious content from infrastructure such as `googleservice[.]xyz`, while displaying forged ISO 27001 or venture-capital documents to mislead victims. Infrastructure pivoting found lookalike venture-capital and cryptocurrency-related domains, including `abiesvc[.]com`, `dekryptcap[.]digital`, `coinbigex[.]com`, and `kraken-dev[.]com`, with some redirecting to legitimate sites for credibility. The source does not attribute the activity to Lazarus, so the summary preserves the observed campaign, targeting, delivery technique, and infrastructure without adding unsupported actor attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 04deb35316ebe1789da042c8876c0622 2020-11-12 2022-01-13
HASH bcf97660ce2b09cbffb454aa5436c9a0 2020-11-12 2022-01-13
HASH cace67b3ea1ce95298933e38311f6d0b 2020-11-12 2022-01-13
HASH af4eefa8cddc1e412fe91ad33199bd71 2020-11-12 2022-01-13
HASH bde4747408ce3cfdfe8238a133ebcac9 2020-11-12 2022-01-13
HASH 389172d2794d789727b9f7d01ec27f75 2020-11-12 2022-01-13
HASH d2f08e227cd528ad8b26e9bbe285ae3c 2020-11-12 2022-01-13
HASH 645adf057b55ef731e624ab435a41757 2020-11-12 2022-01-13
HASH 13ff15ac54a297796e558bb96feaacfd 2020-11-12 2022-01-13
HASH 34239a3607d8b5b8ddd6797855f2e827 2020-11-12 2022-01-13
HASH 421b1e1ab9951d5b8eeda5b041cb0657 2020-11-12 2022-01-13
HASH ecf75bec770edcd89a3c16d3c4edde1a 2020-11-12 2022-01-13
DOMAIN abiesvc.com 2020-11-12 2022-01-13
DOMAIN innoenergy.info 2020-11-12 2022-01-13
DOMAIN kraken-dev.com 2020-11-12 2022-01-13
DOMAIN isosecurity.xyz 2020-11-12 2022-01-13
DOMAIN coinbig.dev 2020-11-12 2022-01-13
DOMAIN coinbigex.com 2020-11-12 2022-01-13
DOMAIN googleservice.xyz 2020-11-12 2022-01-13
DOMAIN abiesvc.info 2020-11-12 2022-01-13
URL https://googleservice.xyz/5+MMs… 2020-11-12 2020-11-12
IPv4 104.168.158.103 2020-11-12 2020-11-12
IPv4 104.168.160.6 2020-11-12 2020-11-12
IPv4 104.168.160.8 2020-11-12 2020-11-12
IPv4 104.168.158.224 2020-11-12 2020-11-12

Related Reports

« Back