Lazarus 그룹 DLL-Side Loading 기법 이용 (2)

2024-01-17 Ahnlab Trojan/Win.LazarLoader.C5572843 (2024.01.12.03)

https://asec.ahnlab.com/ko/60470/

Thumbnail for Lazarus 그룹 DLL-Side Loading 기법 이용 (2)

AhnLab documented a Lazarus DLL side-loading variant that abuses the legitimate Microsoft wmiapsrv.exe binary to load malicious wbemcomn.dll and netutils.dll files from the same directory. The wbemcomn.dll backdoor includes a host validation routine that uses GetSystemFirmwareTable output to decrypt a resource string and load a follow-on file only on the intended system. The related netutils.dll sample loads C:\ProgramData\Microsoft Editor\editor.dat without the same validation step and carries a PDB path pointing to a 7-Zip loader build environment. AhnLab detects the activity as Trojan/Win.LazarLoader variants and lists related MD5 indicators for the malicious DLLs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 21def97a3c5b95df1e1aeb6486881656 2024-01-17 2024-01-23
HASH edca71eda8650a2c591c37c780b6a0c5 2024-01-17 2024-01-23

Related Actors

Related Reports

« Back