疑似Lazarus组织利用大宇造船厂为相关诱饵的系列攻击活动分析
2021-05-10 • Qianxin • Analysis of a series of attack activities by the suspected Lazarus organization using Daewoo Shipbuilding as related bait •
QiAnXin RedDrip analyzes activity suspected to involve Lazarus using Korean-language lures tied to Daewoo Shipbuilding, resident registration forms, and related East Asian themes. The samples used VBA macros to display decoy content, extract an HTA/JavaScript payload hidden in an image resource, and write a Winvoke.exe loader that decrypted and ran a RAT in memory. The malware established persistence through a startup shortcut, used a Microsoft32 mutex, and supported command execution and in-memory code loading from C2. The source links the activity to Lazarus through similarities in macros, second-stage loader behavior, and encryption traits resembling BISTROMATH RAT, while noting the samples mainly targeted East Asia.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f4d46629ca15313b94992f3798718df7 | 2021-05-10 | 2024-07-25 |
| URL | http://snum.or.kr/skin_img/skin… | 2021-05-10 | 2021-12-22 |
| URL | http://www.ddjm.co.kr/bbs/icon/… | 2021-05-10 | 2021-12-22 |
| DOMAIN | snum.or.kr | 2021-05-10 | 2021-12-22 |
| URL | http://www.jinjinpig.co.kr/Anyb… | 2021-04-19 | 2021-12-22 |
| URL | http://mail.namusoft.kr/jsp/use… | 2021-04-19 | 2021-12-22 |
| DOMAIN | mail.namusoft.kr | 2021-04-19 | 2021-12-22 |
| HASH | ed9aa858ba2c4671ca373496a4dd05d4 | 2021-05-10 | 2021-06-15 |
| HASH | 71759cca8c700646b4976b19b9abd6fe | 2021-05-10 | 2021-06-15 |
| HASH | 118cfa75e386ed45bec297f8865de671 | 2021-05-10 | 2021-06-15 |
| HASH | 0812ce08a75e5fc774a114436e88cd06 | 2021-05-10 | 2021-06-15 |
| HASH | d5e974a3386fc99d2932756ca165a451 | 2021-05-10 | 2021-06-15 |
| HASH | 53648bf8f0121130edb42c626d7c2fc4 | 2021-05-10 | 2021-06-15 |
| HASH | 1bb267c96ec2925f6ae3716d831671cf | 2021-05-10 | 2021-06-15 |
| HASH | 4d30612a928faf7643b14bd85d8433cc | 2021-05-10 | 2021-06-15 |
| HASH | 0ecfa51cd4bf1a9841a07bdb5bfcd0ab | 2021-05-10 | 2021-06-15 |
| HASH | 7d7ad10a5d9fa1789b9a918625dbfe35 | 2021-05-10 | 2021-05-10 |