Lazarus 그룹 DLL-Side Loading 기법 이용 (2)
2024-01-17 • Ahnlab • Trojan/Win.LazarLoader.C5572843 (2024.01.12.03) •
AhnLab documented a Lazarus DLL side-loading variant that abuses the legitimate Microsoft wmiapsrv.exe binary to load malicious wbemcomn.dll and netutils.dll files from the same directory. The wbemcomn.dll backdoor includes a host validation routine that uses GetSystemFirmwareTable output to decrypt a resource string and load a follow-on file only on the intended system. The related netutils.dll sample loads C:\ProgramData\Microsoft Editor\editor.dat without the same validation step and carries a PDB path pointing to a 7-Zip loader build environment. AhnLab detects the activity as Trojan/Win.LazarLoader variants and lists related MD5 indicators for the malicious DLLs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 21def97a3c5b95df1e1aeb6486881656 | 2024-01-17 | 2024-01-23 |
| HASH | edca71eda8650a2c591c37c780b6a0c5 | 2024-01-17 | 2024-01-23 |