疑似Lazarus(APT-Q-1)涉及npm包供应链的攻击样本分析
2023-12-08 • Qianxin • Analysis of attack samples suspected of Lazarus (APT-Q-1) involving npm package supply chain •
QiAnXin analyzes downloader samples tied to an npm package supply-chain poisoning incident that it assesses as likely Lazarus based on code overlap with historical Lazarus samples and the group's prior use of supply-chain attacks. The loader decrypts embedded PE and ZIP data, drops IconCache.db and NTUSER.DAT under the user's Roaming Microsoft paths, and establishes persistence through scheduled tasks, HKCU Run, or the Startup folder. The main downloader contacts C2 to request payload metadata, downloads numbered payloads, verifies MD5 hashes, decrypts PE content in memory, and executes specified export functions through rundll32-style loading. The report links the activity to infrastructure including 91.206.178.125, blockchain-newtech.com, chaingrown.com, and 156.236.76.9, while comparing the loading method and constants with earlier Lazarus-linked Comebacker and 3CX-related research.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 91.206.178.125 | 2023-11-04 | 2024-07-05 |
| DOMAIN | blockchain-newtech.com | 2023-12-08 | 2024-05-28 |
| DOMAIN | chaingrown.com | 2023-12-08 | 2024-05-28 |
| URL | https://blockchain-newtech.com/… | 2023-12-08 | 2024-02-28 |
| URL | https://chaingrown.com/manage/m… | 2023-12-08 | 2024-02-28 |
| HASH | 420a13202d271babc32bf8259cdaddf3 | 2023-12-08 | 2024-02-28 |
| IPv4 | 103.179.142.171 | 2023-11-04 | 2024-01-19 |
| HASH | 1c4227bf06121fe9c454a85ad9245b56 | 2023-12-08 | 2023-12-08 |
| HASH | d8a8cc25bf5ef5b96ff7a64f663cbd29 | 2023-12-08 | 2023-12-08 |
| HASH | a6e7c231a699d4efe85080ce5fb36dfb | 2023-12-08 | 2023-12-08 |
| HASH | 46127a35b73b714a9c5c58aaa43cb51f | 2023-12-08 | 2023-12-08 |
| HASH | 7298b1f10ee6afab5e8bf648be1ca13b | 2023-12-08 | 2023-12-08 |
| IPv4 | 156.236.76.9 | 2023-12-08 | 2023-12-08 |