LAZARUS & WATERING-HOLE ATTACKS
2017-02-12 • Bae Systems •
http://baesystemsai.blogspot.kr/2017/02/lazarus-watering-hole-attacks.html
BAE Systems analyzed the Polish financial-sector watering-hole attacks reported by BadCyber and found infrastructure and malware overlaps with other activity against banks in Mexico and Uruguay. The suspected infection path began with the Polish Financial Supervision Authority site redirecting selected visitors to sap.misapor[.]ch and eye-watch[.]in, which hosted malicious JavaScript and payload delivery paths. One available sample unpacked to a malware variant seen in Lazarus tooling during the previous year, using RC4-based decryption, service-installation arguments, and command-and-control behavior. BAE also connected eye-watch[.]in to a Silverlight XAP exploit based on CVE-2016-0034 and noted that similar watering-hole redirects had appeared on the Mexican banking regulator’s site and a Uruguayan bank site. The findings matter because they tie the Polish bank compromises to a broader financial-sector targeting pattern and infrastructure set with Lazarus-toolkit overlap, while keeping some delivery details provisional.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | knf.gov | 2017-02-03 | 2017-05-30 |
| HASH | 85d316590edfb4212049c4490db08c4b | 2017-02-03 | 2017-04-03 |
| HASH | c1364bbf63b3617b25b58209e4529d8c | 2017-02-03 | 2017-04-03 |
| HASH | 1bfbc0c9e0d9ceb5c3f4f6ced6bcfeae | 2017-02-03 | 2017-04-03 |
| DOMAIN | sap.misapor.ch | 2017-02-03 | 2017-04-03 |
| HASH | 6dffcfa68433f886b2e88fd984b4995a | 2017-02-12 | 2017-02-20 |
| HASH | 1507e7a741367745425e0530e23768e6 | 2017-02-12 | 2017-02-12 |
| HASH | 911de8d67af652a87415f8c0a30688b2 | 2017-02-12 | 2017-02-12 |
| HASH | 4cc10ab3f4ee6769e520694a10f611d5 | 2017-02-12 | 2017-02-12 |
| HASH | 7b4a8be258ecb191c4c519d7c486ed8a | 2017-02-12 | 2017-02-12 |
| HASH | cb52c013f7af0219d45953bae663c9a2 | 2017-02-12 | 2017-02-12 |
| HASH | 1f7897b041a812f96f1925138ea38c46 | 2017-02-12 | 2017-02-12 |
| URL | http://brou.com.uy | 2017-02-12 | 2017-02-12 |
| URL | https://www.eye-watch.in/design… | 2017-02-12 | 2017-02-12 |
| URL | http://www.eye-watch.in/jscroll… | 2017-02-12 | 2017-02-12 |
| DOMAIN | brou.com.uy | 2017-02-12 | 2017-02-12 |
| URL | http://sap.misapor.ch/vishop/vi… | 2017-02-03 | 2017-02-12 |
| URL | https://www.eye-watch.in/design… | 2017-02-03 | 2017-02-12 |
| IPv4 | 196.29.166.218 | 2017-02-03 | 2017-02-12 |
| IPv4 | 125.214.195.17 | 2017-02-03 | 2017-02-12 |