주한미군 취업자를 노리는 라자루스 악성코드-미군 구인공고 웹사이트 주소 및 사용방법 안내.zip(2023.07.19)

2023-07-25 Sakai Lazarus malware targeting U.S. military employees in Korea - U.S. military job posting website address and instructions on how to use.zip (2023.07.19)

https://wezard4u.tistory.com/6519

Thumbnail for 주한미군 취업자를 노리는 라자루스 악성코드-미군 구인공고 웹사이트 주소 및 사용방법 안내.zip(2023.07.19)

A Korean analysis describes a Lazarus-attributed ZIP lure aimed at people seeking U.S. Forces Korea employment, disguised as instructions for the Multi National Recruitment System job site. The archive contained decoy PDF material and an LNK file masquerading with a Microsoft Edge icon; the shortcut launched cmd.exe and PowerShell with input redirected from Thumbs.db. Decoded PowerShell downloaded lsasetup.tmp and winrar.exe from jkmusic.co.kr, created scheduled tasks named zuzip and zconshost, and extracted a password-protected payload into ProgramData. The source provides representative hashes for the ZIP and embedded documents, making the lure chain, PowerShell download stage, and persistence commands the key defensive evidence.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://www.jkmusic.co.kr/shop/d… 2023-07-25 2023-07-28
URL http://www.jkmusic.co.kr/shop/d… 2023-07-25 2023-07-28
HASH 66515b6a0e09194511708c1057a62d7… 2023-07-25 2023-07-25
HASH 842b0d0eb01716a9f526acd866d8bad3 2023-07-25 2023-07-25
HASH dfacc251e2f8ca7bab42fb64ef695aa4 2023-07-25 2023-07-25
HASH 0acb06da48d86e1ef15c27a4f5a3bddd 2023-07-25 2023-07-25
HASH 3c5aacd54c4f9baa9a58423b3fe0969d 2023-07-25 2023-07-25
HASH cf47401cca4d7fff2955c7337941ed4b 2023-07-25 2023-07-25
HASH 6c06f97af02acd8c725be3a8419a384f 2023-07-25 2023-07-25
HASH 6277fee38a64f218291c73db5326e1bf 2023-07-25 2023-07-25
HASH 7f4bb17b1011c05d206f62be4685384… 2023-07-25 2023-07-25
DOMAIN korean-air.org 2023-07-21 2023-07-25

Related Reports

« Back