Lazarus武器库更新:Andariel近期攻击样本分析
2022-04-28 • Qianxin • Lazarus weapon library update: Analysis of recent Andariel attack samples •
QiAnXin RedDrip analyzed a set of PE samples attributed by code similarity to Lazarus APT's Andariel sub-group, with activity beginning at least in February 2022 based on VirusTotal submission times. The samples included loaders that decrypted and memory-loaded backdoors or browser password stealers, and Go-based downloaders that collected host details, persisted through scheduled tasks or startup links, and fetched second-stage PE payloads. Reported infrastructure included 109.248.144.155 on ports 8443 and 8080, mail.usengineergroup.com resolving to 109.248.144.136, and additional PHP paths used for C2 communication. The backdoors used DES-decrypted C2 strings and traffic-like markers similar to previously reported Andariel tooling, while the Go downloader's base64-delimited host profiling matched earlier Lazarus downloader tradecraft. The report matters because it shows Andariel continuing to refresh its malware library, including Go malware likely chosen to reduce detection, while preserving recognizable command, configuration, and C2 patterns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 17c46ed7b80c2e4dbea6d0e88ea0827c | 2022-04-28 | 2024-07-25 |
| HASH | 079b4588eaa99a1e802adf5e0b26d8aa | 2022-04-28 | 2024-07-25 |
| HASH | b1c1d28dc7da1d58abab73fa98f60a83 | 2022-04-28 | 2023-02-10 |
| HASH | 5c6f9c83426c6d33ff2d4e72c039b747 | 2022-04-28 | 2023-02-10 |
| HASH | 1875f6a68f70bee316c8a6eda9ebf8de | 2022-04-28 | 2023-02-10 |
| HASH | bdece9758bf34fcad9cba1394519019b | 2022-04-28 | 2023-02-10 |
| HASH | 47791bf9e017e3001ddc68a7351ca2d6 | 2022-04-28 | 2023-02-10 |
| HASH | 2e18350194e59bc6a2a3f6d59da11bd8 | 2022-04-28 | 2023-02-10 |
| HASH | d0e203e8845bf282475a8f816340f2e8 | 2022-04-28 | 2023-02-10 |
| HASH | 85f6e3e3f0bdd0c1b3084fc86ee59d19 | 2022-04-28 | 2023-02-10 |
| HASH | 5130888a0ad3d64ad33c65de696d3fa2 | 2022-04-28 | 2023-02-10 |
| HASH | 5be1e382cd9730fbe386b69bd8045ee7 | 2022-04-28 | 2023-02-10 |
| HASH | 3bd22e0ac965ebb6a18bb71ba39e96dc | 2022-04-28 | 2023-02-10 |
| IPv4 | 155.94.210.11 | 2022-04-28 | 2022-09-08 |
| DOMAIN | mail.usengineergroup.com | 2022-04-28 | 2022-05-12 |
| IPv4 | 193.56.28.32 | 2022-04-28 | 2022-04-28 |
| IPv4 | 45.57.245.17 | 2022-04-28 | 2022-04-28 |
| IPv4 | 109.248.144.155 | 2022-04-28 | 2022-04-28 |
| IPv4 | 109.248.144.136 | 2022-04-28 | 2022-04-28 |