Malicious Documents from Lazarus Group Targeting South Korea
2018-06-22 • Alienvault •
AlienVault analyzed malicious HWP documents linked to Lazarus that targeted South Korean financial and cryptocurrency-related themes, including G20 financial meeting material and documents reportedly connected to the Bithumb theft. The HWP files contained malicious PostScript code that downloaded 32-bit or 64-bit next-stage payloads from tpddata.com paths, and the payload was identified as Manuscrypt. The samples communicated with C2 endpoints impersonating South Korean forum software, including anlway.com, apshenyihl.com, and ap8898.com PHP paths. The report also noted potentially related cryptocurrency phishing domains registered with the same phone number as malware delivery infrastructure, suggesting credential phishing may have accompanied malware delivery. The activity is significant for DPRK tracking because it connects Lazarus tradecraft to South Korean cryptocurrency and financial targets, while noting uncertainty about whether the same malware directly caused the Bithumb theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d8af45210bf931bc5b03215ed30fb73… | 2018-06-22 | 2022-07-31 |
| HASH | 06cfc6cda57fb5b67ee3eb0400dd5b97 | 2018-06-22 | 2019-07-03 |
| DOMAIN | tpddata.com | 2018-06-22 | 2018-09-24 |
| HASH | 69ad5bd4b881d6d1fdb7b19939903e0b | 2018-06-22 | 2018-08-07 |
| HASH | cf09201f02f2edb9c555942a2d6b01d4 | 2018-06-22 | 2018-08-07 |
| HASH | 5b1663d5eb565caccca188b6ff8a362… | 2018-06-22 | 2018-06-22 |
| HASH | 3cde54dce88a4544bf5ffa36066a184… | 2018-06-22 | 2018-06-22 |
| HASH | e76b3fd3e906ac23218b1fbd66fd29c… | 2018-06-22 | 2018-06-22 |
| HASH | 2f4a958b148bef4be10780e8128860c… | 2018-06-22 | 2018-06-22 |
| HASH | 596fbdf01557c3ec89b345c57ae5d9a… | 2018-06-22 | 2018-06-22 |
| HASH | e98991cdd9ddd30adf490673c67a4f8… | 2018-06-22 | 2018-06-22 |
| HASH | 7985af0a87780d27dc52c4f73c38de4… | 2018-06-22 | 2018-06-22 |
| HASH | 58a97c2c731cdf045f26ccc7cba370b… | 2018-06-22 | 2018-06-22 |
| HASH | 485f77e5d32de5dc05510743025a75a… | 2018-06-22 | 2018-06-22 |
| HASH | 4838f85499e3c68415010d4f19e83e2… | 2018-06-22 | 2018-06-22 |
| HASH | 927120588e6c4e5db5b5a1ea9914cd7… | 2018-06-22 | 2018-06-22 |
| HASH | c10363059c57c52501c01f85e3bb435… | 2018-06-22 | 2018-06-22 |
| HASH | afba8105793b635d4ed7febdae4b744… | 2018-06-22 | 2018-06-22 |
| HASH | e498630abe9a91485ba42698a35c2a0… | 2018-06-22 | 2018-06-22 |
| HASH | 2813c0ebcacdcf9052f71d51c81e9c5… | 2018-06-22 | 2018-06-22 |
| URL | https://www.ap8898.com/include/… | 2018-06-22 | 2018-06-22 |
| URL | http://mileage.krb.co.kr/common… | 2018-06-22 | 2018-06-22 |
| URL | http://www.530hr.com/data/commo… | 2018-06-22 | 2018-06-22 |
| URL | http://www.apshenyihl.com/inclu… | 2018-06-22 | 2018-06-22 |
| URL | http://www.33cow.com/include/co… | 2018-06-22 | 2018-06-22 |
| URL | http://www.shieldonline.co.za/s… | 2018-06-22 | 2018-06-22 |
| URL | http://ansetech.co.kr/smartedit… | 2018-06-22 | 2018-06-22 |
| URL | http://www.anlway.com/include/a… | 2018-06-22 | 2018-06-22 |
| URL | http://www.97nb.net/include/arc… | 2018-06-22 | 2018-06-22 |
| URL | http://www.marmarademo.com/incl… | 2018-06-22 | 2018-06-22 |
| URL | https://www.apshenyihl.com/incl… | 2018-06-22 | 2018-06-22 |
| URL | http://www.ap8898.com/include/a… | 2018-06-22 | 2018-06-22 |
| URL | http://www.51up.com/ace/main.asp | 2018-06-22 | 2018-06-22 |
| URL | http://168wangpi.com/include/ch… | 2018-06-22 | 2018-06-22 |
| URL | http://www.028xmz.com/include/c… | 2018-06-22 | 2018-06-22 |
| URL | http://www.paulkaren.com/synthp… | 2018-06-22 | 2018-06-22 |
| URL | http://ando.co.kr/service/s_top… | 2018-06-22 | 2018-06-22 |
| URL | https://www.anlway.com/include/… | 2018-06-22 | 2018-06-22 |
| DOMAIN | bitfiniex.org | 2018-06-22 | 2018-06-22 |
| DOMAIN | coinmaketcape.com | 2018-06-22 | 2018-06-22 |
| DOMAIN | coinoen.org | 2018-06-22 | 2018-06-22 |
| HASH | eb6275a24d047e3be05c2b4e5f50703d | 2018-06-22 | 2018-06-22 |
| HASH | a6d1424e1c33ac7a95eb5b92b923c511 | 2018-06-22 | 2018-06-22 |
| URL | https://tpddata.com/skins/skin-… | 2018-06-22 | 2018-06-22 |
| URL | https://tpddata.com/skins/skin-… | 2018-06-22 | 2018-06-22 |
| DOMAIN | wifispeedcheck.net | 2018-06-22 | 2018-06-22 |
| DOMAIN | itaddnet.com | 2018-06-22 | 2018-06-22 |
| DOMAIN | 168wangpi.com | 2018-03-07 | 2018-06-22 |
| DOMAIN | mileage.krb.co.kr | 2018-03-07 | 2018-06-22 |
| DOMAIN | ansetech.co.kr | 2018-03-07 | 2018-06-22 |
| DOMAIN | ando.co.kr | 2018-03-07 | 2018-06-22 |