Lazarus武器库更新:Andariel近期攻击样本分析

2022-04-28 Qianxin Lazarus weapon library update: Analysis of recent Andariel attack samples

https://mp.weixin.qq.com/s/QfbzuIKUPTXE4GdpBMsGbQ

Thumbnail for Lazarus武器库更新:Andariel近期攻击样本分析

QiAnXin RedDrip analyzed a set of PE samples attributed by code similarity to Lazarus APT's Andariel sub-group, with activity beginning at least in February 2022 based on VirusTotal submission times. The samples included loaders that decrypted and memory-loaded backdoors or browser password stealers, and Go-based downloaders that collected host details, persisted through scheduled tasks or startup links, and fetched second-stage PE payloads. Reported infrastructure included 109.248.144.155 on ports 8443 and 8080, mail.usengineergroup.com resolving to 109.248.144.136, and additional PHP paths used for C2 communication. The backdoors used DES-decrypted C2 strings and traffic-like markers similar to previously reported Andariel tooling, while the Go downloader's base64-delimited host profiling matched earlier Lazarus downloader tradecraft. The report matters because it shows Andariel continuing to refresh its malware library, including Go malware likely chosen to reduce detection, while preserving recognizable command, configuration, and C2 patterns.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 17c46ed7b80c2e4dbea6d0e88ea0827c 2022-04-28 2024-07-25
HASH 079b4588eaa99a1e802adf5e0b26d8aa 2022-04-28 2024-07-25
HASH b1c1d28dc7da1d58abab73fa98f60a83 2022-04-28 2023-02-10
HASH 5c6f9c83426c6d33ff2d4e72c039b747 2022-04-28 2023-02-10
HASH 1875f6a68f70bee316c8a6eda9ebf8de 2022-04-28 2023-02-10
HASH bdece9758bf34fcad9cba1394519019b 2022-04-28 2023-02-10
HASH 47791bf9e017e3001ddc68a7351ca2d6 2022-04-28 2023-02-10
HASH 2e18350194e59bc6a2a3f6d59da11bd8 2022-04-28 2023-02-10
HASH d0e203e8845bf282475a8f816340f2e8 2022-04-28 2023-02-10
HASH 85f6e3e3f0bdd0c1b3084fc86ee59d19 2022-04-28 2023-02-10
HASH 5130888a0ad3d64ad33c65de696d3fa2 2022-04-28 2023-02-10
HASH 5be1e382cd9730fbe386b69bd8045ee7 2022-04-28 2023-02-10
HASH 3bd22e0ac965ebb6a18bb71ba39e96dc 2022-04-28 2023-02-10
IPv4 155.94.210.11 2022-04-28 2022-09-08
DOMAIN mail.usengineergroup.com 2022-04-28 2022-05-12
IPv4 193.56.28.32 2022-04-28 2022-04-28
IPv4 45.57.245.17 2022-04-28 2022-04-28
IPv4 109.248.144.155 2022-04-28 2022-04-28
IPv4 109.248.144.136 2022-04-28 2022-04-28

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back