Lazarus APT组织最新活动揭露

2018-03-07 Tencent Lazarus APT organization's latest activities revealed

https://s.tencent.com/research/report/440.html

Thumbnail for Lazarus APT组织最新活动揭露

Tencent Yujian Threat Intelligence Center reported Lazarus (T-APT-15) activity exploiting Flash `CVE-2018-4878` through spear-phishing documents aimed at targets including cryptocurrency exchanges. The captured `.docx` lures embedded a malicious `.doc` with an exploit SWF that abused a Flash use-after-free condition, modified a `ByteArray` length to gain arbitrary read/write, and ran shellcode that injected into `explorer.exe` before downloading payloads from `falcancoin.io`. Tencent identified the payload as a new `FALLCHILL` remote-control Trojan variant with HTTP C2, remote file/process/information operations, self-uninstall capability, 27 remote-control commands, and C2 paths including `www.530hr.com/data/common.php`, `www.028xmz.com/include/common.php`, and `168wangpi.com/include/charset.php`. The report links the RAT to Lazarus through FALLCHILL code similarity, command-dispatch and logic overlap, Korean resource language, and KR-CERT reporting that North Korean hackers had used the zero-day in the wild.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN 168wangpi.com 2018-03-07 2018-06-22
DOMAIN mileage.krb.co.kr 2018-03-07 2018-06-22
DOMAIN ansetech.co.kr 2018-03-07 2018-06-22
DOMAIN ando.co.kr 2018-03-07 2018-06-22
DOMAIN falcancoin.io 2018-03-07 2018-06-22
IPv4 28.0.0.137 2018-02-02 2018-03-14
HASH 75f2972cc953e26f8fc43eb0456fdc7a 2018-03-07 2018-03-07
HASH f3d6a7b317dfb80dab7a9115691c0016 2018-03-07 2018-03-07
HASH 29e273fcfee8c5a90f4de6214a0fde87 2018-03-07 2018-03-07
HASH c6801f90aaa11ce81c9b66450e002972 2018-03-07 2018-03-07
HASH 66eb4b505f1ae8308fb73906e7d245af 2018-03-07 2018-03-07
HASH 1b3ebec6ce48241c6715e19713a95f1b 2018-03-07 2018-03-07
HASH 74e609f63f5ce332ef58af6b1c95de77 2018-03-07 2018-03-07
HASH 3b1f4d1d0d7a40b449244b8a9e1649ae 2018-03-07 2018-03-07
HASH b778d887a3649fba57a8fb64852ad071 2018-03-07 2018-03-07
HASH 12c786c490366727cf7279fc141921d8 2018-03-07 2018-03-07
DOMAIN hyeolgongdo.com 2018-03-07 2018-03-07
DOMAIN edu4.co.kr 2018-03-07 2018-03-07
IPv4 45.34.66.30 2018-03-07 2018-03-07
IPv4 104.217.233.68 2018-03-07 2018-03-07
IPv4 107.151.163.68 2018-03-07 2018-03-07
DOMAIN daedong.or.kr 2017-04-07 2018-03-07
DOMAIN kosic.or.kr 2017-04-07 2018-03-07

Related Actors

Related Reports

« Back