Lazarus APT组织利用新冠疫情诱饵针对韩国地区的定向攻击分析

2020-04-15 Qianxin Analysis of the Lazarus APT organization's targeted attack targeting South Korea using COVID-19 bait

https://ti.qianxin.com/blog/articles/analysis-of-lazarus-apt-targeted-attack-against-south-korea-using-new-crown-outbreak-bait/

Thumbnail for Lazarus APT组织利用新冠疫情诱饵针对韩国地区的定向攻击分析

QiAnXin RedDrip analyzed Lazarus-attributed targeting of South Korea that used COVID-19 emergency-response lures and HWP attachments impersonating regional disease-control notices. The malicious HWP files contained EPS/PostScript content that executed PowerShell, downloaded DLL payloads such as skype.jpg or h1.jpg from remote servers, and loaded them with regsvr32 or related execution paths. The payloads performed anti-analysis and anti-VM checks, collected user, MAC address, disk, and process information, and supported command execution, file upload, keylogging, and additional download-and-execute functions through C2 infrastructure. Representative infrastructure in the source includes teslacontrols.ir, sofa.rs, kingsvc.cc, and several compromised wp-admin network paths.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://www.kingsvc.cc/index.php 2020-04-02 2020-05-29
URL http://www.sofa.rs/wp-admin/net… 2020-04-02 2020-05-29
HASH fe2d05365f059d48fd972c79afeee682 2020-04-15 2020-05-09
HASH 8451be72b75a38516e7ba7972729909e 2020-04-02 2020-05-09
HASH 4662dfa19bd590b1088befa28426a161 2020-04-15 2020-04-28
URL http://teslacontrols.ir/wp-incl… 2020-04-15 2020-04-28
URL http://teslacontrols.ir/wp-incl… 2020-04-15 2020-04-28
DOMAIN teslacontrols.ir 2020-04-15 2020-04-28
HASH bc13fc599bb594bc19ac9e6fde0c28c6 2020-04-15 2020-04-15
HASH e3ef607182564bb158287cafb7b11be7 2020-04-15 2020-04-15
HASH e6521be3b323865cf05f27d7c43aeff2 2020-04-15 2020-04-15
HASH b5a31d89f5b83d37c921d159364c968c 2020-04-15 2020-04-15
URL http://www.sofa.rs/wp-content/t… 2020-04-15 2020-04-15
URL http://www.mbrainingevents.com/… 2020-04-02 2020-04-15
URL http://www.afuocolento.it/wp-ad… 2020-04-02 2020-04-15

Related Actors

Related Reports

« Back