Dtrackを使った組織侵入型ランサムインシデントの分析

2020-11-27 Macnica Analysis of organizational intrusion ransom incidents using Dtrack

https://security.macnica.co.jp/blog/2020/11/dtrack.html

Thumbnail for Dtrackを使った組織侵入型ランサムインシデントの分析

Macnica analyzed a ransomware intrusion at an overseas site of a Japanese company where attackers encrypted dozens of servers and backups after gaining domain administrator access. The initial compromise abused CVE-2020-10189 in an internet-exposed Zoho ManageEngine Desktop Central server to install Cobalt Strike, then investigators found msupdate.exe, identified as Lazarus-linked Dtrack, downloaded through BITS on the same server. The attackers later used RDP, PowerShell stagers, domain controller access, and Jetico BestCrypt to encrypt server volumes within five days. Macnica noted the early tradecraft resembled APT41 reporting, but the Dtrack discovery required considering Lazarus involvement while avoiding firm attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f91f2a7e1944734371562f18b066f19… 2020-11-27 2020-11-27
HASH b72c2c98b4679c05706a07e069d75fb… 2020-11-27 2020-11-27
HASH 85d8822ea120dc87321400d03b527ce… 2020-11-27 2020-11-27
HASH 859f845ee7c741f34ce8bd53d0fe806… 2020-11-27 2020-11-27
HASH de9ef08a148305963accb8a64eb2211… 2020-11-27 2020-11-27
URL http://www.tastygoodness.net/mo… 2020-11-27 2020-11-27
URL https://mail.gietriangle.org/pu… 2020-11-27 2020-11-27
URL http://ussainc.org/includes/dat… 2020-11-27 2020-11-27
DOMAIN ussainc.org 2020-11-27 2020-11-27
DOMAIN mail.gietriangle.org 2020-11-27 2020-11-27
DOMAIN exchange.dumb1.com 2020-11-27 2020-11-27
IPv4 176.123.3.108 2020-11-27 2020-11-27
IPv4 66.42.98.220 2020-11-27 2020-11-27
IPv4 91.208.184.78 2020-11-27 2020-11-27

Related Reports

« Back