近期Lazarus持续针对加密货币行业展开攻击活动 - 安恒威胁情报中心

2022-06-02 安恒信息 Recently, Lazarus has continued to launch attacks against the cryptocurrency industry - Anheng Threat Intelligence Center

https://starmap.dbappsecurity.com.cn/blog/articles/2022/06/02/lazarus-has-continued-to-attack-the-cryptocurrency-industry/

Thumbnail for 近期Lazarus持续针对加密货币行业展开攻击活动 - 安恒威胁情报中心

Anheng’s Hunting Shadow Lab reported suspected Lazarus activity, likely associated with the BlueNorOff subgroup, targeting venture capital and cryptocurrency themes through encrypted document lures. The samples used ZIP files containing protected PDFs and fake Password.txt LNK files that executed obfuscated commands, launched mshta, fetched HTA scripts, and deployed follow-on payloads. One analyzed chain contacted hobobot[.]net, downloaded cry.exe and then crypto.exe from filebin[.]net, and ended with a Cobalt Strike payload using 100.26.34[.]10 as its team server. The report highlights a continuation of Lazarus cryptocurrency targeting since at least 2017, with evolution from macro/VBS delivery toward LNK, mshta, and more heavily obfuscated PowerShell while retaining similar social-engineering patterns.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 52b0b06ab4cf6c6b1a13d8eec2705e3b 2022-06-02 2022-06-22
HASH 03933959de20c3d1d40567b7d7fc4f7e 2022-06-02 2022-06-02
HASH add43c15cd1a1ec7428259e568cc5da6 2022-06-02 2022-06-02
HASH 1d96f2c73b421a213bef1b08ce787ad9 2022-06-02 2022-06-02
HASH bc2eab8dfc5a0f85eb04eeb1fa19eb91 2022-06-02 2022-06-02
HASH f03dad1037de1748ec6b4824a46b403a 2022-06-02 2022-06-02
HASH eeb160ba05372385f1aafde004f3d94e 2022-06-02 2022-06-02
HASH 662c1e091bf1041fa6d7a2bb5c7c1df3 2022-06-02 2022-06-02
HASH fdae3718aa57ac35798633569a45dcdd 2022-06-02 2022-06-02
HASH b9b53d54106166ea8413a25937a0d618 2022-06-02 2022-06-02
HASH bac259d6c5f337fd1aa6e6585c62effd 2022-06-02 2022-06-02
HASH 03b8e448cd7393c3433bdd7f52494bb6 2022-06-02 2022-06-02
HASH c1b8bf3074e095e020322f5c1a42a351 2022-06-02 2022-06-02
HASH 97fa3040290e37cd78f65ff809da3ea9 2022-06-02 2022-06-02
HASH d1f8908e8f8b4428ab08ab4b11fae2ef 2022-06-02 2022-06-02
HASH 312924b5621af460700519460fda83e8 2022-06-02 2022-06-02
HASH 42d0caf67df74583f892e1d8c3ea661b 2022-06-02 2022-06-02
HASH 6f69d65470e49709ba4ee9673ea95367 2022-06-02 2022-06-02
HASH 46cd0a89bcf4f3baae4a39321447f212 2022-06-02 2022-06-02
HASH 9b582f1e491069d096ea89fcd2dfada2 2022-06-02 2022-06-02
HASH 2fcc47e632de2bef56f6199ce1dd654d 2022-06-02 2022-06-02
HASH 1364f98ccac7821d101950f716f07437 2022-06-02 2022-06-02
HASH 2042c81ce21f499575c3f3d0cff48972 2022-06-02 2022-06-02
HASH f9d22163a36878c350022e0bd6361fff 2022-06-02 2022-06-02
HASH 7091702dde4efb13cb9a9a53c45bf670 2022-06-02 2022-06-02
HASH 2aeb8ae658fbb02c112bf912d7e32abc 2022-06-02 2022-06-02
URL https://hobobot.net/%EB%A7%AC%E… 2022-06-02 2022-06-02
URL https://filebin.net/ddb2m9ywgcf… 2022-06-02 2022-06-02
URL https://hobobot.net/cry.exe 2022-06-02 2022-06-02
DOMAIN hobobot.net 2022-06-02 2022-06-02
DOMAIN cry.com 2022-06-02 2022-06-02
IPv4 174.138.24.107 2022-06-02 2022-06-02
IPv4 100.26.34.10 2022-06-02 2022-06-02
IPv4 54.80.204.133 2022-06-02 2022-06-02
IPv4 54.226.210.44 2022-06-02 2022-06-02

Related Reports

« Back