윈도우 IIS 웹 서버를 노리는 Lazarus 그룹
2023-05-17 • Ahnlab • Lazarus group targeting Windows IIS web servers •
AhnLab observed Lazarus targeting poorly managed or vulnerable Windows IIS web servers by using the IIS worker process w3wp.exe to stage Wordconv.exe with a malicious msvcr100.dll and msvcr100.dat in the same directory. The malicious DLL used DLL side-loading to decrypt and execute an encoded PE with Salsa20, resembled the earlier cylvc.dll loader, and likely delivered a backdoor-style payload. Follow-on activity abused a Notepad++ Color Picker plugin DLL, diagn.dll, to decrypt another payload with RC6; AhnLab telemetry showed access to lsass.exe memory, suggesting credential theft. The actor then used stolen credentials for internal reconnaissance and lateral movement over RDP, underscoring Lazarus's continued use of side-loading and exposed-server access for enterprise intrusion.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 228732b45ed1ca3cda2b2721f5f5667c | 2023-05-17 | 2023-05-23 |
| HASH | e501bb6762c14baafadbde8b0c04bbd6 | 2023-05-17 | 2023-05-23 |
| HASH | 47d380dd587db977bf6458ec767fee3d | 2023-05-17 | 2023-05-23 |
| HASH | 4d91cd34a9aae8f2d88e0f77e812cef7 | 2022-10-24 | 2023-05-23 |
| URL | https://www.samdb.or.kr/info/pi… | 2023-05-17 | 2023-05-17 |