虚拟货币收割机:Lazarus APT组织近期不断攻击加密货币行业 - 安恒威胁情报中心

2022-08-17 安恒信息 Virtual currency harvester: Lazarus APT organization has been continuously attacking the cryptocurrency industry recently - Anheng Threat Intelligence Center

https://starmap.dbappsecurity.com.cn/blog/articles/2022/08/17/lazarus-group-continues-to-launch-attacks-on-the-cryptocurrency-industry-2/

Thumbnail for 虚拟货币收割机:Lazarus APT组织近期不断攻击加密货币行业 - 安恒威胁情报中心

DBAPPSecurity's Lieying Lab attributed a series of cryptocurrency-sector attacks to Lazarus, noting repeated activity against blockchain and cryptocurrency organizations and a recent attack on deBridge. The campaign used phishing emails with attachments or links to malicious archives, including lures such as Ledger Nano security patch manuals and job descriptions aimed at cryptocurrency companies including woo.network. A analyzed ZIP delivered a disguised LNK file that copied and renamed msiexec.exe, invoked it through pcalua.exe, downloaded a remote MSI, and executed embedded scripts to open a decoy PDF, create Edge.lnk persistence, inspect antivirus-related processes with WMI, and run a second-stage JavaScript command loop. The report highlights Lazarus' evolution from Office macros and mshta-based LNK execution toward MSI-based payload delivery, renamed LOLBins, obfuscation, and file-sharing-themed infrastructure such as documentshare[.]info, fclouddown[.]co, googlesheet[.]info, and 155.138.219[.]140.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b94a13586828f8f3474f7b89755f5e7… 2022-08-17 2023-10-13
DOMAIN shconstmarket.com 2022-08-17 2023-10-04
DOMAIN dps.shconstmarket.com 2022-08-17 2023-10-04
IPv4 155.138.219.140 2022-08-17 2023-05-22
HASH 57099b79a9824765f8be07471ec33c4… 2022-08-17 2022-08-17
HASH 5a9086a16870bde828b8f50be08bdca… 2022-08-17 2022-08-17
HASH 9dc813afe2ff8963696691d5092b9ea… 2022-08-17 2022-08-17
HASH 81554ae36513b4a637d72db864f31e3… 2022-08-17 2022-08-17
HASH f7ed3c959efaf1bab7c291d74840c91… 2022-08-17 2022-08-17
HASH 184fba6160521bd8c345d327e42ad28… 2022-08-17 2022-08-17
HASH be9bfcb781c90759f9d13bb4edffdb5… 2022-08-17 2022-08-17
HASH 6904be55212c4464ae09dda50fad1b3… 2022-08-17 2022-08-17
HASH 801789ec161b7749c8d9f59049754e0… 2022-08-17 2022-08-17
HASH b2ed5f272a518368cc453b940460b41… 2022-08-17 2022-08-17
HASH d917667ea076239fc8969f52520a2c6… 2022-08-17 2022-08-17
HASH ab269279818db7e98c9c8899ad8e7a2… 2022-08-17 2022-08-17
HASH 57ce525263ce8b9bb29773dd2a8389f… 2022-08-17 2022-08-17
HASH a6cffde5684ca81e4f19ba77300bb25… 2022-08-17 2022-08-17
HASH 2772bbe0d1e643d0dbf860ee7fc2b24… 2022-08-17 2022-08-17
HASH 1dbf893e2289c5175a12a38c65ad0ab… 2022-08-17 2022-08-17
HASH 3c64d557fb5d83b6df1d2963f4b3f9a… 2022-08-17 2022-08-17
HASH eaef808e1ac99d13481b23b9dbdb6d2… 2022-08-17 2022-08-17
HASH f1ade73b9c61f2f4b774a1b5003a5d7… 2022-08-17 2022-08-17
HASH 73f684b87139927012db12ec8d92824… 2022-08-17 2022-08-17
HASH d6e3922b0bcb8aa6f5a4c62ef263c80… 2022-08-17 2022-08-17
HASH 899b2da752ad50f525e364f0af930de… 2022-08-17 2022-08-17
HASH 82f446528560789d2f79a9c5f1b8cf3… 2022-08-17 2022-08-17
HASH bcfa523b1d55fcadc89bfee8f7c9aba… 2022-08-17 2022-08-17
HASH 07df3733b75e6e23d2217a6548ed666… 2022-08-17 2022-08-17
HASH a80884ac34c1bc3b351bb30a95ca194… 2022-08-17 2022-08-17
HASH 6047a46276a3231b0d3d6626cf4a864… 2022-08-17 2022-08-17
HASH 0f52e0d8febf08be311010c7273a26a… 2022-08-17 2022-08-17
HASH 0fe69e67286203ca2dcd080b4c25ab7… 2022-08-17 2022-08-17
HASH bab26cb256e097096ab1cac5dd77f95… 2022-08-17 2022-08-17
HASH ff44d3dabb82467cd21187039789314… 2022-08-17 2022-08-17
HASH b3f39054043551bcb78e4531580899b… 2022-08-17 2022-08-17
HASH 57959c2be2ac6349aa37edb73cd8a88… 2022-08-17 2022-08-17
HASH 1e154b2976cc00d457c0dc2b83ebe81… 2022-08-17 2022-08-17
HASH b8bc45d9e038dc32b2cdee90f196103… 2022-08-17 2022-08-17
HASH 1b41b9cc8a632d76eaf4cd73aa39565… 2022-08-17 2022-08-17
HASH e40347e7cd335b43a0d27b335216847… 2022-08-17 2022-08-17
HASH 8b2871e08f6a88df33ac198a2db87bc… 2022-08-17 2022-08-17
HASH e4c9fe57a22be3a31be9d3c4309f885… 2022-08-17 2022-08-17
HASH f7170b70a89f4b5d196e3a09c1d6135… 2022-08-17 2022-08-17
HASH 422384d25aa351a4eb6871ea50c3c96… 2022-08-17 2022-08-17
HASH 8eec3ac9f7d1ac64fc7397ba57cdac4… 2022-08-17 2022-08-17
HASH d6fcaf76b6837551e40184279c466e0… 2022-08-17 2022-08-17
HASH 45c0007e4c744c6f9ba43660cc7edb9… 2022-08-17 2022-08-17
HASH fa95222a70b29260c83829d9add596a… 2022-08-17 2022-08-17
HASH bcafd808237f1f29bdae4e45d75d925… 2022-08-17 2022-08-17
HASH c285bf15a83133b231afddbbcfe1c35… 2022-08-17 2022-08-17
HASH ebadd662bb797b5077e24638de04a15… 2022-08-17 2022-08-17
HASH 6d0aa8ebc1287eb55fdca521c2c70c8… 2022-08-17 2022-08-17
HASH 3debe73d29fd2c0a8eca0f701c30870… 2022-08-17 2022-08-17
DOMAIN fclouddown.co 2022-08-17 2022-08-17
DOMAIN googlesheet.info 2022-08-17 2022-08-17
DOMAIN doc.documentshare.info 2022-08-17 2022-08-17
DOMAIN inst.shconstmarket.com 2022-08-17 2022-08-17
DOMAIN documentshare.info 2022-08-17 2022-08-17
DOMAIN file.fclouddown.co 2022-08-17 2022-08-17
IPv4 162.33.179.165 2022-08-17 2022-08-17
« Back