Lazarus Group Targeting Windows IIS Web Servers

2023-05-23 Ahnlab

https://asec.ahnlab.com/en/53132/

Thumbnail for Lazarus Group Targeting Windows IIS Web Servers

AhnLab reports Lazarus attacks against vulnerable Windows IIS web servers in which malicious activity is launched through the w3wp.exe IIS worker process. The actor places Wordconv.exe, msvcr100.dll, and msvcr100.dat on the server, then uses DLL side-loading so msvcr100.dll decrypts a Salsa20-encoded PE from the .dat file and executes it in memory before cleaning itself up. Follow-on activity includes abuse of a Notepad++ color-picker plugin through diagn.dll, RC6-encrypted payload loading, suspected credential theft from lsass.exe, internal reconnaissance, and RDP lateral movement. AhnLab links msvcr100.dll to earlier Lazarus cylvc.dll-style loaders and recommends monitoring abnormal process relationships and exposed web-server attack surface.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 228732b45ed1ca3cda2b2721f5f5667c 2023-05-17 2023-05-23
HASH e501bb6762c14baafadbde8b0c04bbd6 2023-05-17 2023-05-23
HASH 47d380dd587db977bf6458ec767fee3d 2023-05-17 2023-05-23
HASH 4d91cd34a9aae8f2d88e0f77e812cef7 2022-10-24 2023-05-23

Related Actors

Related Reports

« Back