疑似Lazarus组织利用大宇造船厂为相关诱饵的系列攻击活动分析

2021-05-10 Qianxin Analysis of a series of attack activities by the suspected Lazarus organization using Daewoo Shipbuilding as related bait

https://www.secrss.com/articles/31112

Thumbnail for 疑似Lazarus组织利用大宇造船厂为相关诱饵的系列攻击活动分析

QiAnXin RedDrip analyzes activity suspected to involve Lazarus using Korean-language lures tied to Daewoo Shipbuilding, resident registration forms, and related East Asian themes. The samples used VBA macros to display decoy content, extract an HTA/JavaScript payload hidden in an image resource, and write a Winvoke.exe loader that decrypted and ran a RAT in memory. The malware established persistence through a startup shortcut, used a Microsoft32 mutex, and supported command execution and in-memory code loading from C2. The source links the activity to Lazarus through similarities in macros, second-stage loader behavior, and encryption traits resembling BISTROMATH RAT, while noting the samples mainly targeted East Asia.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f4d46629ca15313b94992f3798718df7 2021-05-10 2024-07-25
URL http://snum.or.kr/skin_img/skin… 2021-05-10 2021-12-22
URL http://www.ddjm.co.kr/bbs/icon/… 2021-05-10 2021-12-22
DOMAIN snum.or.kr 2021-05-10 2021-12-22
URL http://www.jinjinpig.co.kr/Anyb… 2021-04-19 2021-12-22
URL http://mail.namusoft.kr/jsp/use… 2021-04-19 2021-12-22
DOMAIN mail.namusoft.kr 2021-04-19 2021-12-22
HASH ed9aa858ba2c4671ca373496a4dd05d4 2021-05-10 2021-06-15
HASH 71759cca8c700646b4976b19b9abd6fe 2021-05-10 2021-06-15
HASH 118cfa75e386ed45bec297f8865de671 2021-05-10 2021-06-15
HASH 0812ce08a75e5fc774a114436e88cd06 2021-05-10 2021-06-15
HASH d5e974a3386fc99d2932756ca165a451 2021-05-10 2021-06-15
HASH 53648bf8f0121130edb42c626d7c2fc4 2021-05-10 2021-06-15
HASH 1bb267c96ec2925f6ae3716d831671cf 2021-05-10 2021-06-15
HASH 4d30612a928faf7643b14bd85d8433cc 2021-05-10 2021-06-15
HASH 0ecfa51cd4bf1a9841a07bdb5bfcd0ab 2021-05-10 2021-06-15
HASH 7d7ad10a5d9fa1789b9a918625dbfe35 2021-05-10 2021-05-10

Related Actors

Related Reports

« Back