掘金行动(Operation Gold Hunting) - 目标瞄准前沿科技行业 - 安恒威胁情报中心
2020-11-12 • 安恒信息 • Operation Gold Hunting - Targeting cutting-edge technology industries - Anheng Threat Intelligence Center •
https://starmap.dbappsecurity.com.cn/blog/articles/2020/11/12/operation-gold-hunting/
DBAPPSecurity’s Operation Gold Hunting report describes phishing documents aimed at venture-capital and frontier-technology targets, using NDA and investment-presentation themes as lures. The analyzed DOCX files used remote template injection to fetch malicious content from infrastructure such as `googleservice[.]xyz`, while displaying forged ISO 27001 or venture-capital documents to mislead victims. Infrastructure pivoting found lookalike venture-capital and cryptocurrency-related domains, including `abiesvc[.]com`, `dekryptcap[.]digital`, `coinbigex[.]com`, and `kraken-dev[.]com`, with some redirecting to legitimate sites for credibility. The source does not attribute the activity to Lazarus, so the summary preserves the observed campaign, targeting, delivery technique, and infrastructure without adding unsupported actor attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 04deb35316ebe1789da042c8876c0622 | 2020-11-12 | 2022-01-13 |
| HASH | bcf97660ce2b09cbffb454aa5436c9a0 | 2020-11-12 | 2022-01-13 |
| HASH | cace67b3ea1ce95298933e38311f6d0b | 2020-11-12 | 2022-01-13 |
| HASH | af4eefa8cddc1e412fe91ad33199bd71 | 2020-11-12 | 2022-01-13 |
| HASH | bde4747408ce3cfdfe8238a133ebcac9 | 2020-11-12 | 2022-01-13 |
| HASH | 389172d2794d789727b9f7d01ec27f75 | 2020-11-12 | 2022-01-13 |
| HASH | d2f08e227cd528ad8b26e9bbe285ae3c | 2020-11-12 | 2022-01-13 |
| HASH | 645adf057b55ef731e624ab435a41757 | 2020-11-12 | 2022-01-13 |
| HASH | 13ff15ac54a297796e558bb96feaacfd | 2020-11-12 | 2022-01-13 |
| HASH | 34239a3607d8b5b8ddd6797855f2e827 | 2020-11-12 | 2022-01-13 |
| HASH | 421b1e1ab9951d5b8eeda5b041cb0657 | 2020-11-12 | 2022-01-13 |
| HASH | ecf75bec770edcd89a3c16d3c4edde1a | 2020-11-12 | 2022-01-13 |
| DOMAIN | abiesvc.com | 2020-11-12 | 2022-01-13 |
| DOMAIN | innoenergy.info | 2020-11-12 | 2022-01-13 |
| DOMAIN | kraken-dev.com | 2020-11-12 | 2022-01-13 |
| DOMAIN | isosecurity.xyz | 2020-11-12 | 2022-01-13 |
| DOMAIN | coinbig.dev | 2020-11-12 | 2022-01-13 |
| DOMAIN | coinbigex.com | 2020-11-12 | 2022-01-13 |
| DOMAIN | googleservice.xyz | 2020-11-12 | 2022-01-13 |
| DOMAIN | abiesvc.info | 2020-11-12 | 2022-01-13 |
| URL | https://googleservice.xyz/5+MMs… | 2020-11-12 | 2020-11-12 |
| IPv4 | 104.168.158.103 | 2020-11-12 | 2020-11-12 |
| IPv4 | 104.168.160.6 | 2020-11-12 | 2020-11-12 |
| IPv4 | 104.168.160.8 | 2020-11-12 | 2020-11-12 |
| IPv4 | 104.168.158.224 | 2020-11-12 | 2020-11-12 |