Dtrackを使った組織侵入型ランサムインシデントの分析
2020-11-27 • Macnica • Analysis of organizational intrusion ransom incidents using Dtrack •
Macnica analyzed a ransomware intrusion at an overseas site of a Japanese company where attackers encrypted dozens of servers and backups after gaining domain administrator access. The initial compromise abused CVE-2020-10189 in an internet-exposed Zoho ManageEngine Desktop Central server to install Cobalt Strike, then investigators found msupdate.exe, identified as Lazarus-linked Dtrack, downloaded through BITS on the same server. The attackers later used RDP, PowerShell stagers, domain controller access, and Jetico BestCrypt to encrypt server volumes within five days. Macnica noted the early tradecraft resembled APT41 reporting, but the Dtrack discovery required considering Lazarus involvement while avoiding firm attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f91f2a7e1944734371562f18b066f19… | 2020-11-27 | 2020-11-27 |
| HASH | b72c2c98b4679c05706a07e069d75fb… | 2020-11-27 | 2020-11-27 |
| HASH | 85d8822ea120dc87321400d03b527ce… | 2020-11-27 | 2020-11-27 |
| HASH | 859f845ee7c741f34ce8bd53d0fe806… | 2020-11-27 | 2020-11-27 |
| HASH | de9ef08a148305963accb8a64eb2211… | 2020-11-27 | 2020-11-27 |
| URL | http://www.tastygoodness.net/mo… | 2020-11-27 | 2020-11-27 |
| URL | https://mail.gietriangle.org/pu… | 2020-11-27 | 2020-11-27 |
| URL | http://ussainc.org/includes/dat… | 2020-11-27 | 2020-11-27 |
| DOMAIN | ussainc.org | 2020-11-27 | 2020-11-27 |
| DOMAIN | mail.gietriangle.org | 2020-11-27 | 2020-11-27 |
| DOMAIN | exchange.dumb1.com | 2020-11-27 | 2020-11-27 |
| IPv4 | 176.123.3.108 | 2020-11-27 | 2020-11-27 |
| IPv4 | 66.42.98.220 | 2020-11-27 | 2020-11-27 |
| IPv4 | 91.208.184.78 | 2020-11-27 | 2020-11-27 |