攻撃グループLazarusによる攻撃オペレーション

2021-01-26 JPCERT Attack operation by attack group Lazarus

https://blogs.jpcert.or.jp/ja/2021/01/Lazarus_malware2.html

Thumbnail for 攻撃グループLazarusによる攻撃オペレーション

JPCERT/CC describes two Lazarus/Hidden Cobra malware families, Torisma and LCPDot, used during intrusion and post-intrusion operations. Torisma is a rundll32-launched downloader that reads configuration files, uses a fixed signature and VEST-32 encryption key, sends HTTP POST requests to C2 servers, and downloads encrypted modules that can collect infected-host data or execute files. LCPDot is another downloader, sometimes VMProtect-obfuscated, that appears to support lateral movement after Torisma infections and uses options for RC4 keys and Base64-encoded C2 information. The report documents protocol details, configuration paths, encoded communications, and representative C2 URLs for defenders to hunt in affected environments.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://inovecommerce.com.br/pu… 2021-01-26 2021-04-27
DOMAIN mail.clicktocareers.com 2021-01-26 2021-04-27
DOMAIN inovecommerce.com.br 2021-01-26 2021-04-27
DOMAIN akramportal.org 2021-01-26 2021-04-27
DOMAIN vega.mh-tec.jp 2020-12-15 2021-04-27
HASH ff7172d9c888b7a88a7d77372112d772 2021-01-26 2021-01-28
HASH a9334efa9f40a36e7dde7ef1fe3018b… 2021-01-26 2021-01-28
HASH f77a9875dbf1a1807082117d69bdbdd… 2021-01-26 2021-01-26
HASH 9ae9ed06a69baa24e3a539d9ce32c43… 2021-01-26 2021-01-26
HASH ba57f8fcb28b7d1085e2e5e24bf2a46… 2021-01-26 2021-01-26
HASH 0c69fd9be0cc9fadacff2c0bacf59da… 2021-01-26 2021-01-26
HASH 7762ba7ae989d47446da21cd04fd6fb… 2021-01-26 2021-01-26
URL http://www.hirokawaunso.co.jp/w… 2021-01-26 2021-01-26
URL https://www.index-consulting.jp… 2021-01-26 2021-01-26
URL https://www.scimpex.com/admin/a… 2021-01-26 2021-01-26
URL https://ja-fc.or.jp/shop/shoppi… 2021-01-26 2021-01-26
URL http://kenpa.org/yokohama/main.… 2021-01-26 2021-01-26
URL https://www.fabianiarte.com/new… 2021-01-26 2021-01-26
URL https://mail.clicktocareers.com… 2021-01-26 2021-01-26
URL https://akramportal.org/public/… 2021-01-26 2021-01-26
URL https://www.leemble.com/5mai-ly… 2021-01-26 2021-01-26
URL https://www.commodore.com.tr/mo… 2021-01-26 2021-01-26
URL https://www.tronslog.com/public… 2021-01-26 2021-01-26
URL https://vega.mh-tec.jp:443/.wel… 2021-01-26 2021-01-26
DOMAIN kenpa.org 2021-01-26 2021-01-26
DOMAIN ja-fc.or.jp 2021-01-26 2021-01-26

Related Actors

Related Reports

« Back