Lazarus Group Targeting Windows IIS Web Servers
2023-05-23 • Ahnlab •
AhnLab reports Lazarus attacks against vulnerable Windows IIS web servers in which malicious activity is launched through the w3wp.exe IIS worker process. The actor places Wordconv.exe, msvcr100.dll, and msvcr100.dat on the server, then uses DLL side-loading so msvcr100.dll decrypts a Salsa20-encoded PE from the .dat file and executes it in memory before cleaning itself up. Follow-on activity includes abuse of a Notepad++ color-picker plugin through diagn.dll, RC6-encrypted payload loading, suspected credential theft from lsass.exe, internal reconnaissance, and RDP lateral movement. AhnLab links msvcr100.dll to earlier Lazarus cylvc.dll-style loaders and recommends monitoring abnormal process relationships and exposed web-server attack surface.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 228732b45ed1ca3cda2b2721f5f5667c | 2023-05-17 | 2023-05-23 |
| HASH | e501bb6762c14baafadbde8b0c04bbd6 | 2023-05-17 | 2023-05-23 |
| HASH | 47d380dd587db977bf6458ec767fee3d | 2023-05-17 | 2023-05-23 |
| HASH | 4d91cd34a9aae8f2d88e0f77e812cef7 | 2022-10-24 | 2023-05-23 |