攻撃グループLazarusが使用するマルウェアYamaBot

2022-06-30 JPCERT Malware used by the Lazarus attack group: YamaBot

https://blogs.jpcert.or.jp/ja/2022/06/yamabot.html

Thumbnail for 攻撃グループLazarusが使用するマルウェアYamaBot

JPCERT/CC attributes YamaBot use to the Lazarus attack group and describes recently observed Windows variants alongside earlier Linux samples. YamaBot is written in Go and communicates with C2 servers over HTTP, sending Base64-encoded User-Agent data and RC4-encrypted, Base64-encoded host information or command output in cookie values such as captcha_session and captcha_val. The Windows variant includes functions such as download, file path/PID reporting, mutex handling, and shell command execution, while the Linux variant is described as limited to running shell commands through /bin/sh. The report lists C2 paths including www.karin-store.com/recaptcha.php, yoshinorihirano.net/wp-includes/feed-xml.php, and 213.180.180.154/editor/session/aaa000/support.php, and emphasizes that investigators should examine both Windows endpoints and Linux servers.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f226086b5959eb96bd30dec0ffcbf0f… 2022-06-30 2024-07-25
HASH 6db57bbc2d07343dd6ceba0f53c7375… 2022-06-30 2024-07-25
IPv4 213.180.180.154 2022-06-30 2022-09-08
URL http://yoshinorihirano.net/wp-i… 2022-06-30 2022-07-12
URL http://www.karin-store.com/reca… 2022-06-30 2022-07-12
DOMAIN yoshinorihirano.net 2022-06-30 2022-07-12

Related Actors

Related Reports

« Back