라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습
2019-03-27 • ESTSecurity • Lazarus Group counterattacks APT targeting Israeli military companies •
ESRC investigated reporting that Lazarus-linked operators targeted Israeli defense and aerospace-related organizations through spear-phishing, including Israel Military Industries and Ashot Ashkelon Industries. The lure impersonated a SysAid software update in Hebrew and delivered a RAR file that internally used the ACE format and CVE-2018-20250 to place a malicious executable in the Windows Startup path. The payload, ekrnview.exe, was a 64-bit Windows executable that queried host information, checked Windows product data, and contacted hardcoded C2 endpoints including alahbabgroup.com, 103.225.168.159, khuyay.org, and 47.91.56.21. The same 103.225.168.159 address appeared in a crafted LNK icon path, and one C2 server exposed directory listing and a B374k web shell, giving defenders infrastructure and tooling artifacts to compare with related Middle East WinRAR exploit activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2eb447785e5b35c42d842706d593a90… | 2019-03-27 | 2020-03-09 |
| HASH | 431c792fcc8ba9b58f0ffde5c8fe6fd… | 2019-03-27 | 2019-03-27 |
| HASH | 102d3104a010e49f92a6903adc92c449 | 2019-03-27 | 2019-03-27 |
| HASH | 314e8105f28530eb0bf54891b9b3ff69 | 2019-03-27 | 2019-03-27 |
| URL | http://www.alahbabgroup.com/bak… | 2019-03-27 | 2019-03-27 |
| URL | http://www.khuyay.org/odin_back… | 2019-03-27 | 2019-03-27 |
| IPv4 | 198.96.95.58 | 2019-03-27 | 2019-03-27 |
| IPv4 | 170.239.84.243 | 2019-03-27 | 2019-03-27 |
| HASH | 96986b18a8470f4020ea78df0b3db7d4 | 2019-03-26 | 2019-03-27 |
| IPv4 | 47.91.56.21 | 2019-03-26 | 2019-03-27 |
| IPv4 | 103.225.168.159 | 2019-03-26 | 2019-03-27 |