LAZARUS & WATERING-HOLE ATTACKS

2017-02-12 Bae Systems

http://baesystemsai.blogspot.kr/2017/02/lazarus-watering-hole-attacks.html

Thumbnail for LAZARUS & WATERING-HOLE ATTACKS

BAE Systems analyzed the Polish financial-sector watering-hole attacks reported by BadCyber and found infrastructure and malware overlaps with other activity against banks in Mexico and Uruguay. The suspected infection path began with the Polish Financial Supervision Authority site redirecting selected visitors to sap.misapor[.]ch and eye-watch[.]in, which hosted malicious JavaScript and payload delivery paths. One available sample unpacked to a malware variant seen in Lazarus tooling during the previous year, using RC4-based decryption, service-installation arguments, and command-and-control behavior. BAE also connected eye-watch[.]in to a Silverlight XAP exploit based on CVE-2016-0034 and noted that similar watering-hole redirects had appeared on the Mexican banking regulator’s site and a Uruguayan bank site. The findings matter because they tie the Polish bank compromises to a broader financial-sector targeting pattern and infrastructure set with Lazarus-toolkit overlap, while keeping some delivery details provisional.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN knf.gov 2017-02-03 2017-05-30
HASH 85d316590edfb4212049c4490db08c4b 2017-02-03 2017-04-03
HASH c1364bbf63b3617b25b58209e4529d8c 2017-02-03 2017-04-03
HASH 1bfbc0c9e0d9ceb5c3f4f6ced6bcfeae 2017-02-03 2017-04-03
DOMAIN sap.misapor.ch 2017-02-03 2017-04-03
HASH 6dffcfa68433f886b2e88fd984b4995a 2017-02-12 2017-02-20
HASH 1507e7a741367745425e0530e23768e6 2017-02-12 2017-02-12
HASH 911de8d67af652a87415f8c0a30688b2 2017-02-12 2017-02-12
HASH 4cc10ab3f4ee6769e520694a10f611d5 2017-02-12 2017-02-12
HASH 7b4a8be258ecb191c4c519d7c486ed8a 2017-02-12 2017-02-12
HASH cb52c013f7af0219d45953bae663c9a2 2017-02-12 2017-02-12
HASH 1f7897b041a812f96f1925138ea38c46 2017-02-12 2017-02-12
URL http://brou.com.uy 2017-02-12 2017-02-12
URL https://www.eye-watch.in/design… 2017-02-12 2017-02-12
URL http://www.eye-watch.in/jscroll… 2017-02-12 2017-02-12
DOMAIN brou.com.uy 2017-02-12 2017-02-12
URL http://sap.misapor.ch/vishop/vi… 2017-02-03 2017-02-12
URL https://www.eye-watch.in/design… 2017-02-03 2017-02-12
IPv4 196.29.166.218 2017-02-03 2017-02-12
IPv4 125.214.195.17 2017-02-03 2017-02-12

Related Actors

Related Reports

« Back