近期Lazarus持续针对加密货币行业展开攻击活动 - 安恒威胁情报中心
2022-06-02 • 安恒信息 • Recently, Lazarus has continued to launch attacks against the cryptocurrency industry - Anheng Threat Intelligence Center •
Anheng’s Hunting Shadow Lab reported suspected Lazarus activity, likely associated with the BlueNorOff subgroup, targeting venture capital and cryptocurrency themes through encrypted document lures. The samples used ZIP files containing protected PDFs and fake Password.txt LNK files that executed obfuscated commands, launched mshta, fetched HTA scripts, and deployed follow-on payloads. One analyzed chain contacted hobobot[.]net, downloaded cry.exe and then crypto.exe from filebin[.]net, and ended with a Cobalt Strike payload using 100.26.34[.]10 as its team server. The report highlights a continuation of Lazarus cryptocurrency targeting since at least 2017, with evolution from macro/VBS delivery toward LNK, mshta, and more heavily obfuscated PowerShell while retaining similar social-engineering patterns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 52b0b06ab4cf6c6b1a13d8eec2705e3b | 2022-06-02 | 2022-06-22 |
| HASH | 03933959de20c3d1d40567b7d7fc4f7e | 2022-06-02 | 2022-06-02 |
| HASH | add43c15cd1a1ec7428259e568cc5da6 | 2022-06-02 | 2022-06-02 |
| HASH | 1d96f2c73b421a213bef1b08ce787ad9 | 2022-06-02 | 2022-06-02 |
| HASH | bc2eab8dfc5a0f85eb04eeb1fa19eb91 | 2022-06-02 | 2022-06-02 |
| HASH | f03dad1037de1748ec6b4824a46b403a | 2022-06-02 | 2022-06-02 |
| HASH | eeb160ba05372385f1aafde004f3d94e | 2022-06-02 | 2022-06-02 |
| HASH | 662c1e091bf1041fa6d7a2bb5c7c1df3 | 2022-06-02 | 2022-06-02 |
| HASH | fdae3718aa57ac35798633569a45dcdd | 2022-06-02 | 2022-06-02 |
| HASH | b9b53d54106166ea8413a25937a0d618 | 2022-06-02 | 2022-06-02 |
| HASH | bac259d6c5f337fd1aa6e6585c62effd | 2022-06-02 | 2022-06-02 |
| HASH | 03b8e448cd7393c3433bdd7f52494bb6 | 2022-06-02 | 2022-06-02 |
| HASH | c1b8bf3074e095e020322f5c1a42a351 | 2022-06-02 | 2022-06-02 |
| HASH | 97fa3040290e37cd78f65ff809da3ea9 | 2022-06-02 | 2022-06-02 |
| HASH | d1f8908e8f8b4428ab08ab4b11fae2ef | 2022-06-02 | 2022-06-02 |
| HASH | 312924b5621af460700519460fda83e8 | 2022-06-02 | 2022-06-02 |
| HASH | 42d0caf67df74583f892e1d8c3ea661b | 2022-06-02 | 2022-06-02 |
| HASH | 6f69d65470e49709ba4ee9673ea95367 | 2022-06-02 | 2022-06-02 |
| HASH | 46cd0a89bcf4f3baae4a39321447f212 | 2022-06-02 | 2022-06-02 |
| HASH | 9b582f1e491069d096ea89fcd2dfada2 | 2022-06-02 | 2022-06-02 |
| HASH | 2fcc47e632de2bef56f6199ce1dd654d | 2022-06-02 | 2022-06-02 |
| HASH | 1364f98ccac7821d101950f716f07437 | 2022-06-02 | 2022-06-02 |
| HASH | 2042c81ce21f499575c3f3d0cff48972 | 2022-06-02 | 2022-06-02 |
| HASH | f9d22163a36878c350022e0bd6361fff | 2022-06-02 | 2022-06-02 |
| HASH | 7091702dde4efb13cb9a9a53c45bf670 | 2022-06-02 | 2022-06-02 |
| HASH | 2aeb8ae658fbb02c112bf912d7e32abc | 2022-06-02 | 2022-06-02 |
| URL | https://hobobot.net/%EB%A7%AC%E… | 2022-06-02 | 2022-06-02 |
| URL | https://filebin.net/ddb2m9ywgcf… | 2022-06-02 | 2022-06-02 |
| URL | https://hobobot.net/cry.exe | 2022-06-02 | 2022-06-02 |
| DOMAIN | hobobot.net | 2022-06-02 | 2022-06-02 |
| DOMAIN | cry.com | 2022-06-02 | 2022-06-02 |
| IPv4 | 174.138.24.107 | 2022-06-02 | 2022-06-02 |
| IPv4 | 100.26.34.10 | 2022-06-02 | 2022-06-02 |
| IPv4 | 54.80.204.133 | 2022-06-02 | 2022-06-02 |
| IPv4 | 54.226.210.44 | 2022-06-02 | 2022-06-02 |