Lazarus组织对加密货币行业持续发起攻击 - 安恒威胁情报中心
2020-11-24 • 安恒信息 • The Lazarus group continues to launch attacks on the cryptocurrency industry - Anheng Threat Intelligence Center •
DBAPPSecurity attributed a set of cryptocurrency-themed LNK attacks to Lazarus activity against exchanges, industry staff, and digital-currency users. One Japanese-language lure masqueraded as business guidance and executed `mshta` through a Bitly short link, fetched decoy content from Google Drive, checked for security processes such as Kingsoft and NPAV, and ran a base64-encoded script that beaconed to C2 every 15 seconds for follow-on payloads. The report links related samples through shared usernames, document metadata, Korean language settings, and similar TTPs from earlier Lazarus cryptocurrency campaigns. It also identifies associated infrastructure such as `up.myemail[.]works`, `filehost[.]network`, and Google Drive decoy links.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 84.201.189.216 | 2020-11-24 | 2021-02-01 |
| HASH | a164164ef82fa17605c49c36c67a6244 | 2020-11-24 | 2021-01-28 |
| HASH | 14a00f517012279af53118a491253e5c | 2020-11-24 | 2021-01-28 |
| HASH | 12aa32ee18926c597f3c0387f0775577 | 2020-11-24 | 2021-01-28 |
| HASH | 224d2398437e665f3202d4118e4748e2 | 2020-11-24 | 2021-01-28 |
| IPv4 | 89.134.49.3 | 2020-11-24 | 2021-01-28 |
| HASH | fb1c6e467956ec29c098bb18474a2ef6 | 2020-11-24 | 2020-11-24 |
| HASH | c1f725abaf4e82ff1a4042f84d226643 | 2020-11-24 | 2020-11-24 |
| HASH | 9d555c1093ff84ac3d442b1a0617f7ef | 2020-11-24 | 2020-11-24 |
| HASH | 0efc5c754b6739be19d5478fdffde7f5 | 2020-11-24 | 2020-11-24 |
| HASH | 4da5e7d083af1ba3872c205ff27de8cc | 2020-11-24 | 2020-11-24 |
| HASH | f316f341f923c1598dbbb6967c1c66e2 | 2020-11-24 | 2020-11-24 |
| HASH | a2bfa52ac21ab618fb7f8af1261b6428 | 2020-11-24 | 2020-11-24 |
| HASH | a2117f2058043ef757af6e5d45afa491 | 2020-11-24 | 2020-11-24 |
| URL | http://up.myemail.works/+Eu8cue… | 2020-11-24 | 2020-11-24 |
| URL | http://up.myemail.works/GezS0o/… | 2020-11-24 | 2020-11-24 |
| DOMAIN | sharesvr.net | 2020-11-24 | 2020-11-24 |
| DOMAIN | cloud-sheet.net | 2020-11-24 | 2020-11-24 |
| DOMAIN | msftoffice.com | 2020-11-24 | 2020-11-24 |
| DOMAIN | anicloud.ru | 2020-11-24 | 2020-11-24 |
| DOMAIN | up.myemail.works | 2020-11-24 | 2020-11-24 |