주한미군 취업자를 노리는 라자루스 악성코드-미군 구인공고 웹사이트 주소 및 사용방법 안내.zip(2023.07.19)
2023-07-25 • Sakai • Lazarus malware targeting U.S. military employees in Korea - U.S. military job posting website address and instructions on how to use.zip (2023.07.19) •
A Korean analysis describes a Lazarus-attributed ZIP lure aimed at people seeking U.S. Forces Korea employment, disguised as instructions for the Multi National Recruitment System job site. The archive contained decoy PDF material and an LNK file masquerading with a Microsoft Edge icon; the shortcut launched cmd.exe and PowerShell with input redirected from Thumbs.db. Decoded PowerShell downloaded lsasetup.tmp and winrar.exe from jkmusic.co.kr, created scheduled tasks named zuzip and zconshost, and extracted a password-protected payload into ProgramData. The source provides representative hashes for the ZIP and embedded documents, making the lure chain, PowerShell download stage, and persistence commands the key defensive evidence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://www.jkmusic.co.kr/shop/d… | 2023-07-25 | 2023-07-28 |
| URL | http://www.jkmusic.co.kr/shop/d… | 2023-07-25 | 2023-07-28 |
| HASH | 66515b6a0e09194511708c1057a62d7… | 2023-07-25 | 2023-07-25 |
| HASH | 842b0d0eb01716a9f526acd866d8bad3 | 2023-07-25 | 2023-07-25 |
| HASH | dfacc251e2f8ca7bab42fb64ef695aa4 | 2023-07-25 | 2023-07-25 |
| HASH | 0acb06da48d86e1ef15c27a4f5a3bddd | 2023-07-25 | 2023-07-25 |
| HASH | 3c5aacd54c4f9baa9a58423b3fe0969d | 2023-07-25 | 2023-07-25 |
| HASH | cf47401cca4d7fff2955c7337941ed4b | 2023-07-25 | 2023-07-25 |
| HASH | 6c06f97af02acd8c725be3a8419a384f | 2023-07-25 | 2023-07-25 |
| HASH | 6277fee38a64f218291c73db5326e1bf | 2023-07-25 | 2023-07-25 |
| HASH | 7f4bb17b1011c05d206f62be4685384… | 2023-07-25 | 2023-07-25 |
| DOMAIN | korean-air.org | 2023-07-21 | 2023-07-25 |