INITECH 프로세스를 악용하는 라자루스 공격 그룹의 신종 악성코드

2022-04-18 Ahnlab New malware from the Lazarus attack group that exploits the INITECH process

https://asec.ahnlab.com/ko/33706/

Thumbnail for INITECH 프로세스를 악용하는 라자루스 공격 그룹의 신종 악성코드

AhnLab ASEC reported that Lazarus malware infections were observed in about 47 companies and organizations during Q1 2022, including defense-sector victims. The activity abused the legitimate INITECH INISAFE CrossWeb EX process inisafecrosswebexsvc.exe, which had not been modified, by injecting the malicious SCSKAppLink.dll into it. When injected into that host process, the malware connected to a materic.or.kr path to download an additional payload, saved as main_top[1].htm and copied to C:\Users\Public\SCSKAppLink.dll. ASEC linked the activity to broader Lazarus operations against defense and chemical-sector targets and listed related malware families including LazarAgent, LazarShell, Outlook infostealers, port scanners, keyloggers, and multiple C2 URLs and hashes.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN materic.or.kr 2022-04-18 2023-06-14
HASH 0ac90c7ad1be57f705e3c42380cbcccd 2022-04-18 2023-04-12
HASH b974bc9e6f375f301ae2f75d1e8b6783 2022-04-18 2023-04-12
HASH adf0d4bbefccf342493e02538155e611 2022-04-18 2023-04-12
HASH 1e7d604fadd7d481dfadb66b9313865d 2022-04-18 2023-02-15
HASH 7870decbc7578da1656d1d1ff992313c 2022-04-18 2023-02-15
HASH b3e03a41ced8c8baa56b8b78f1d55c22 2022-04-18 2023-02-15
HASH b213063f28e308adadf63d3b506e794e 2022-04-18 2022-10-07
HASH a329ac7215369469d72b93c1bac1c3c4 2022-04-18 2022-04-18
HASH e6265dccfdef1d1aa134aec6236734f8 2022-04-18 2022-04-18
HASH 933b640d26e397122ce8de9293705d71 2022-04-18 2022-04-18
HASH d9bc5edce4b1c4a941b0bf8e3fac3ea8 2022-04-18 2022-04-18
HASH 683713a93337f343149a5b3836475c5d 2022-04-18 2022-04-18
HASH f48369111f2faabb0ccb5d1d90491e0e 2022-04-18 2022-04-18
HASH ec99ebb78857211eb52eb84750d070e7 2022-04-18 2022-04-18
HASH 2ef844ed5dcb9b8b38ebde3b1e2a450c 2022-04-18 2022-04-18
HASH d57f8cd2f49e34beda94b0f90426f7b3 2022-04-18 2022-04-18
HASH dd3710abfacdf381801bb11cf142bd29 2022-04-18 2022-04-18
HASH a8b90b2dd98c4fdd4ae84a075a5a9473 2022-04-18 2022-04-18
HASH 0775d753aeaebc1cff491e42c8950ec0 2022-04-18 2022-04-18
HASH f15fd25a4c6e94e2202090bbb82ebc39 2022-04-18 2022-04-18
HASH e8d7eaf96b3e5aee219013c55682968c 2022-04-18 2022-04-18
HASH e04206ba707de4cde94efeda6752d0ca 2022-04-18 2022-04-18
HASH d3bfa72cc8f6f8d3d822395dbc8cd8b8 2022-04-18 2022-04-18
HASH 81e922198d00be3e6d41dce773c6a7fb 2022-04-18 2022-04-18
HASH 8fcdf6506ca05efafc5af35e0f09b341 2022-04-18 2022-04-18
HASH 7bf6b3cd3b3034abb0967975e56f0a4b 2022-04-18 2022-04-18
HASH 0f994f841c54702de0277f19b1ac8c77 2022-04-18 2022-04-18
HASH 6a240b2edc1ca2b652dbed44b27cb05f 2022-04-18 2022-04-18
HASH 4b96d9ca051fc68518b5a21a35f001d0 2022-04-18 2022-04-18
HASH b85fde972ee618a225bfba1cef369cc8 2022-04-18 2022-04-18
HASH 5349c845499a6387823ff823fccaa229 2022-04-18 2022-04-18
HASH 878ad11012a2e965ea845311fb1b059f 2022-04-18 2022-04-18
HASH 570f65824f055de16ef1c392e2e4503a 2022-04-18 2022-04-18
HASH c99d5e7edba670515b7b8a4a32986149 2022-04-18 2022-04-18
HASH 4e2dfd387addee4de615a57a2008cfc6 2022-04-18 2022-04-18
HASH b5eaec8ce02d684baa3646f39e8bc9b5 2022-04-18 2022-04-18
HASH 196fe14b4ec963ba98bbaf4a23a47aef 2022-04-18 2022-04-18
HASH 4541efd1c54b53a3d11532cb885b2202 2022-04-18 2022-04-18
HASH 7607ef6426f659042d3f1ffbfea13e6a 2022-04-18 2022-04-18
HASH e84404ded7096cd42ef39847de002361 2022-04-18 2022-04-18
HASH 6929caa7831ae2600410bc5664f692b3 2022-04-18 2022-04-18
HASH 39457097686668a2f937818a62560fe7 2022-04-18 2022-04-18
HASH bb9f5141c53e74c9d80dce1c1a2a13f0 2022-04-18 2022-04-18
HASH 7188f827d8106f563980b3ccf5558c23 2022-04-18 2022-04-18
HASH 3ecd26bacd9dd73819908cba972db66b 2022-04-18 2022-04-18
HASH dd759642659d7b2c7fd365cbeff4942e 2022-04-18 2022-04-18
HASH 3d7e3781bd0b89ba88c08aa443b11fe5 2022-04-18 2022-04-18
HASH cb5401c760b89d80657fc0efc605ae62 2022-04-18 2022-04-18
HASH b91d1a5cc4a1de0493c1a9a9727db6f9 2022-04-18 2022-04-18
URL https://www.okkids.kr/html/prog… 2022-04-18 2022-04-18
URL https://www.gaonwell.com/data/b… 2022-04-18 2022-04-18
URL https://materic.or.kr/include/m… 2022-04-18 2022-04-18
URL https://www.materic.or.kr/inclu… 2022-04-18 2022-04-18
URL https://www.shoppingbagsdirect.… 2022-04-18 2022-04-18
URL http://www.h-cube.co.kr/main/im… 2022-04-18 2022-04-18
URL https://www.namchoncc.co.kr/inc… 2022-04-18 2022-04-18

Related Actors

Related Reports

« Back