라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습

2019-03-27 ESTSecurity Lazarus Group counterattacks APT targeting Israeli military companies

https://blog.alyac.co.kr/2219

Thumbnail for 라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습

ESRC investigated reporting that Lazarus-linked operators targeted Israeli defense and aerospace-related organizations through spear-phishing, including Israel Military Industries and Ashot Ashkelon Industries. The lure impersonated a SysAid software update in Hebrew and delivered a RAR file that internally used the ACE format and CVE-2018-20250 to place a malicious executable in the Windows Startup path. The payload, ekrnview.exe, was a 64-bit Windows executable that queried host information, checked Windows product data, and contacted hardcoded C2 endpoints including alahbabgroup.com, 103.225.168.159, khuyay.org, and 47.91.56.21. The same 103.225.168.159 address appeared in a crafted LNK icon path, and one C2 server exposed directory listing and a B374k web shell, giving defenders infrastructure and tooling artifacts to compare with related Middle East WinRAR exploit activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2eb447785e5b35c42d842706d593a90… 2019-03-27 2020-03-09
HASH 431c792fcc8ba9b58f0ffde5c8fe6fd… 2019-03-27 2019-03-27
HASH 102d3104a010e49f92a6903adc92c449 2019-03-27 2019-03-27
HASH 314e8105f28530eb0bf54891b9b3ff69 2019-03-27 2019-03-27
URL http://www.alahbabgroup.com/bak… 2019-03-27 2019-03-27
URL http://www.khuyay.org/odin_back… 2019-03-27 2019-03-27
IPv4 198.96.95.58 2019-03-27 2019-03-27
IPv4 170.239.84.243 2019-03-27 2019-03-27
HASH 96986b18a8470f4020ea78df0b3db7d4 2019-03-26 2019-03-27
IPv4 47.91.56.21 2019-03-26 2019-03-27
IPv4 103.225.168.159 2019-03-26 2019-03-27

Related Actors

Related Reports

« Back