攻撃グループLazarusによる攻撃オペレーション
2021-01-26 • JPCERT • Attack operation by attack group Lazarus •
JPCERT/CC describes two Lazarus/Hidden Cobra malware families, Torisma and LCPDot, used during intrusion and post-intrusion operations. Torisma is a rundll32-launched downloader that reads configuration files, uses a fixed signature and VEST-32 encryption key, sends HTTP POST requests to C2 servers, and downloads encrypted modules that can collect infected-host data or execute files. LCPDot is another downloader, sometimes VMProtect-obfuscated, that appears to support lateral movement after Torisma infections and uses options for RC4 keys and Base64-encoded C2 information. The report documents protocol details, configuration paths, encoded communications, and representative C2 URLs for defenders to hunt in affected environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://inovecommerce.com.br/pu… | 2021-01-26 | 2021-04-27 |
| DOMAIN | mail.clicktocareers.com | 2021-01-26 | 2021-04-27 |
| DOMAIN | inovecommerce.com.br | 2021-01-26 | 2021-04-27 |
| DOMAIN | akramportal.org | 2021-01-26 | 2021-04-27 |
| DOMAIN | vega.mh-tec.jp | 2020-12-15 | 2021-04-27 |
| HASH | ff7172d9c888b7a88a7d77372112d772 | 2021-01-26 | 2021-01-28 |
| HASH | a9334efa9f40a36e7dde7ef1fe3018b… | 2021-01-26 | 2021-01-28 |
| HASH | f77a9875dbf1a1807082117d69bdbdd… | 2021-01-26 | 2021-01-26 |
| HASH | 9ae9ed06a69baa24e3a539d9ce32c43… | 2021-01-26 | 2021-01-26 |
| HASH | ba57f8fcb28b7d1085e2e5e24bf2a46… | 2021-01-26 | 2021-01-26 |
| HASH | 0c69fd9be0cc9fadacff2c0bacf59da… | 2021-01-26 | 2021-01-26 |
| HASH | 7762ba7ae989d47446da21cd04fd6fb… | 2021-01-26 | 2021-01-26 |
| URL | http://www.hirokawaunso.co.jp/w… | 2021-01-26 | 2021-01-26 |
| URL | https://www.index-consulting.jp… | 2021-01-26 | 2021-01-26 |
| URL | https://www.scimpex.com/admin/a… | 2021-01-26 | 2021-01-26 |
| URL | https://ja-fc.or.jp/shop/shoppi… | 2021-01-26 | 2021-01-26 |
| URL | http://kenpa.org/yokohama/main.… | 2021-01-26 | 2021-01-26 |
| URL | https://www.fabianiarte.com/new… | 2021-01-26 | 2021-01-26 |
| URL | https://mail.clicktocareers.com… | 2021-01-26 | 2021-01-26 |
| URL | https://akramportal.org/public/… | 2021-01-26 | 2021-01-26 |
| URL | https://www.leemble.com/5mai-ly… | 2021-01-26 | 2021-01-26 |
| URL | https://www.commodore.com.tr/mo… | 2021-01-26 | 2021-01-26 |
| URL | https://www.tronslog.com/public… | 2021-01-26 | 2021-01-26 |
| URL | https://vega.mh-tec.jp:443/.wel… | 2021-01-26 | 2021-01-26 |
| DOMAIN | kenpa.org | 2021-01-26 | 2021-01-26 |
| DOMAIN | ja-fc.or.jp | 2021-01-26 | 2021-01-26 |