Lazarus APT组织利用新冠疫情诱饵针对韩国地区的定向攻击分析
2020-04-15 • Qianxin • Analysis of the Lazarus APT organization's targeted attack targeting South Korea using COVID-19 bait •
QiAnXin RedDrip analyzed Lazarus-attributed targeting of South Korea that used COVID-19 emergency-response lures and HWP attachments impersonating regional disease-control notices. The malicious HWP files contained EPS/PostScript content that executed PowerShell, downloaded DLL payloads such as skype.jpg or h1.jpg from remote servers, and loaded them with regsvr32 or related execution paths. The payloads performed anti-analysis and anti-VM checks, collected user, MAC address, disk, and process information, and supported command execution, file upload, keylogging, and additional download-and-execute functions through C2 infrastructure. Representative infrastructure in the source includes teslacontrols.ir, sofa.rs, kingsvc.cc, and several compromised wp-admin network paths.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://www.kingsvc.cc/index.php | 2020-04-02 | 2020-05-29 |
| URL | http://www.sofa.rs/wp-admin/net… | 2020-04-02 | 2020-05-29 |
| HASH | fe2d05365f059d48fd972c79afeee682 | 2020-04-15 | 2020-05-09 |
| HASH | 8451be72b75a38516e7ba7972729909e | 2020-04-02 | 2020-05-09 |
| HASH | 4662dfa19bd590b1088befa28426a161 | 2020-04-15 | 2020-04-28 |
| URL | http://teslacontrols.ir/wp-incl… | 2020-04-15 | 2020-04-28 |
| URL | http://teslacontrols.ir/wp-incl… | 2020-04-15 | 2020-04-28 |
| DOMAIN | teslacontrols.ir | 2020-04-15 | 2020-04-28 |
| HASH | bc13fc599bb594bc19ac9e6fde0c28c6 | 2020-04-15 | 2020-04-15 |
| HASH | e3ef607182564bb158287cafb7b11be7 | 2020-04-15 | 2020-04-15 |
| HASH | e6521be3b323865cf05f27d7c43aeff2 | 2020-04-15 | 2020-04-15 |
| HASH | b5a31d89f5b83d37c921d159364c968c | 2020-04-15 | 2020-04-15 |
| URL | http://www.sofa.rs/wp-content/t… | 2020-04-15 | 2020-04-15 |
| URL | http://www.mbrainingevents.com/… | 2020-04-02 | 2020-04-15 |
| URL | http://www.afuocolento.it/wp-ad… | 2020-04-02 | 2020-04-15 |