Lazarus APT组织最新活动揭露
2018-03-07 • Tencent • Lazarus APT organization's latest activities revealed •
Tencent Yujian Threat Intelligence Center reported Lazarus (T-APT-15) activity exploiting Flash `CVE-2018-4878` through spear-phishing documents aimed at targets including cryptocurrency exchanges. The captured `.docx` lures embedded a malicious `.doc` with an exploit SWF that abused a Flash use-after-free condition, modified a `ByteArray` length to gain arbitrary read/write, and ran shellcode that injected into `explorer.exe` before downloading payloads from `falcancoin.io`. Tencent identified the payload as a new `FALLCHILL` remote-control Trojan variant with HTTP C2, remote file/process/information operations, self-uninstall capability, 27 remote-control commands, and C2 paths including `www.530hr.com/data/common.php`, `www.028xmz.com/include/common.php`, and `168wangpi.com/include/charset.php`. The report links the RAT to Lazarus through FALLCHILL code similarity, command-dispatch and logic overlap, Korean resource language, and KR-CERT reporting that North Korean hackers had used the zero-day in the wild.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | 168wangpi.com | 2018-03-07 | 2018-06-22 |
| DOMAIN | mileage.krb.co.kr | 2018-03-07 | 2018-06-22 |
| DOMAIN | ansetech.co.kr | 2018-03-07 | 2018-06-22 |
| DOMAIN | ando.co.kr | 2018-03-07 | 2018-06-22 |
| DOMAIN | falcancoin.io | 2018-03-07 | 2018-06-22 |
| IPv4 | 28.0.0.137 | 2018-02-02 | 2018-03-14 |
| HASH | 75f2972cc953e26f8fc43eb0456fdc7a | 2018-03-07 | 2018-03-07 |
| HASH | f3d6a7b317dfb80dab7a9115691c0016 | 2018-03-07 | 2018-03-07 |
| HASH | 29e273fcfee8c5a90f4de6214a0fde87 | 2018-03-07 | 2018-03-07 |
| HASH | c6801f90aaa11ce81c9b66450e002972 | 2018-03-07 | 2018-03-07 |
| HASH | 66eb4b505f1ae8308fb73906e7d245af | 2018-03-07 | 2018-03-07 |
| HASH | 1b3ebec6ce48241c6715e19713a95f1b | 2018-03-07 | 2018-03-07 |
| HASH | 74e609f63f5ce332ef58af6b1c95de77 | 2018-03-07 | 2018-03-07 |
| HASH | 3b1f4d1d0d7a40b449244b8a9e1649ae | 2018-03-07 | 2018-03-07 |
| HASH | b778d887a3649fba57a8fb64852ad071 | 2018-03-07 | 2018-03-07 |
| HASH | 12c786c490366727cf7279fc141921d8 | 2018-03-07 | 2018-03-07 |
| DOMAIN | hyeolgongdo.com | 2018-03-07 | 2018-03-07 |
| DOMAIN | edu4.co.kr | 2018-03-07 | 2018-03-07 |
| IPv4 | 45.34.66.30 | 2018-03-07 | 2018-03-07 |
| IPv4 | 104.217.233.68 | 2018-03-07 | 2018-03-07 |
| IPv4 | 107.151.163.68 | 2018-03-07 | 2018-03-07 |
| DOMAIN | daedong.or.kr | 2017-04-07 | 2018-03-07 |
| DOMAIN | kosic.or.kr | 2017-04-07 | 2018-03-07 |