윈도우 IIS 웹 서버를 노리는 Lazarus 그룹

2023-05-17 Ahnlab Lazarus group targeting Windows IIS web servers

https://asec.ahnlab.com/ko/52829/

AhnLab observed Lazarus targeting poorly managed or vulnerable Windows IIS web servers by using the IIS worker process w3wp.exe to stage Wordconv.exe with a malicious msvcr100.dll and msvcr100.dat in the same directory. The malicious DLL used DLL side-loading to decrypt and execute an encoded PE with Salsa20, resembled the earlier cylvc.dll loader, and likely delivered a backdoor-style payload. Follow-on activity abused a Notepad++ Color Picker plugin DLL, diagn.dll, to decrypt another payload with RC6; AhnLab telemetry showed access to lsass.exe memory, suggesting credential theft. The actor then used stolen credentials for internal reconnaissance and lateral movement over RDP, underscoring Lazarus's continued use of side-loading and exposed-server access for enterprise intrusion.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 228732b45ed1ca3cda2b2721f5f5667c 2023-05-17 2023-05-23
HASH e501bb6762c14baafadbde8b0c04bbd6 2023-05-17 2023-05-23
HASH 47d380dd587db977bf6458ec767fee3d 2023-05-17 2023-05-23
HASH 4d91cd34a9aae8f2d88e0f77e812cef7 2022-10-24 2023-05-23
URL https://www.samdb.or.kr/info/pi… 2023-05-17 2023-05-17

Related Actors

Related Reports

« Back