북한 해킹 단체 라자루스(Lazarus) 추측이 되는 악성코드-WerFault.lnk(2024.8.19)
2024-08-28 • Sakai • Malware Suspected to Be from the North Korean Hacking Group Lazarus - WerFault.lnk (2024.8.19) •
A Korean malware analysis describes a WerFault.lnk sample assessed by the author as likely tied to a North Korean APT, while the exact cluster remains uncertain among Lazarus, Kimsuky, Konni, or another DPRK-linked group. The LNK copies the legitimate Windows WerFault.exe to %temp%, runs hidden PowerShell, finds a same-sized LNK file, XOR-decodes embedded bytes with 0x71, writes the payload as %temp%\faultrep.dll, and launches the copied WerFault.exe for side-loading. The extracted DLL checks for VirtualBox, VMware, and Xen-related processes such as vboxservice.exe, vmtoolsd.exe, vmware.exe, and xenservice.exe, indicating anti-analysis logic. The source also lists hashes for the LNK and DLL and notes broad antivirus detection of the DLL as Kryptik, Ulise, Wacatac, Rozena, or generic Trojan malware.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e0c3282206b5533bb3272741212cb6e1 | 2024-08-28 | 2024-08-28 |
| HASH | bdf6730d5c52821e237a7ceb47d8838d | 2024-08-28 | 2024-08-28 |
| HASH | ac7772803e0f65522f43357cb31b0b0… | 2024-08-28 | 2024-08-28 |
| HASH | 164107e62657aed8fe29d026f8a78fd… | 2024-08-28 | 2024-08-28 |
| HASH | 0dda91a21b6f6536715eb83f21c75451 | 2024-08-28 | 2024-08-28 |
| HASH | 0b1d881b010b2230a5ba9e5d9a0f0d3… | 2024-08-28 | 2024-08-28 |
| HASH | 5162e8b479835c2aff439bf5a0c5e70… | 2024-08-28 | 2024-08-28 |
| HASH | e4b8e64ba6493120c7728bddc844e628 | 2024-08-28 | 2024-08-28 |