북한 해킹 단체 라자루스(Lazarus) 추측이 되는 악성코드-WerFault.lnk(2024.8.19)

2024-08-28 Sakai Malware Suspected to Be from the North Korean Hacking Group Lazarus - WerFault.lnk (2024.8.19)

https://wezard4u.tistory.com/429263

Thumbnail for 북한 해킹 단체 라자루스(Lazarus) 추측이 되는 악성코드-WerFault.lnk(2024.8.19)

A Korean malware analysis describes a WerFault.lnk sample assessed by the author as likely tied to a North Korean APT, while the exact cluster remains uncertain among Lazarus, Kimsuky, Konni, or another DPRK-linked group. The LNK copies the legitimate Windows WerFault.exe to %temp%, runs hidden PowerShell, finds a same-sized LNK file, XOR-decodes embedded bytes with 0x71, writes the payload as %temp%\faultrep.dll, and launches the copied WerFault.exe for side-loading. The extracted DLL checks for VirtualBox, VMware, and Xen-related processes such as vboxservice.exe, vmtoolsd.exe, vmware.exe, and xenservice.exe, indicating anti-analysis logic. The source also lists hashes for the LNK and DLL and notes broad antivirus detection of the DLL as Kryptik, Ulise, Wacatac, Rozena, or generic Trojan malware.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e0c3282206b5533bb3272741212cb6e1 2024-08-28 2024-08-28
HASH bdf6730d5c52821e237a7ceb47d8838d 2024-08-28 2024-08-28
HASH ac7772803e0f65522f43357cb31b0b0… 2024-08-28 2024-08-28
HASH 164107e62657aed8fe29d026f8a78fd… 2024-08-28 2024-08-28
HASH 0dda91a21b6f6536715eb83f21c75451 2024-08-28 2024-08-28
HASH 0b1d881b010b2230a5ba9e5d9a0f0d3… 2024-08-28 2024-08-28
HASH 5162e8b479835c2aff439bf5a0c5e70… 2024-08-28 2024-08-28
HASH e4b8e64ba6493120c7728bddc844e628 2024-08-28 2024-08-28

Related Actors

Related Reports

« Back