Malicious Documents from Lazarus Group Targeting South Korea

2018-06-22 Alienvault

https://www.alienvault.com/blogs/labs-research/malicious-documents-from-lazarus-group-targeting-south-korea

AlienVault analyzed malicious HWP documents linked to Lazarus that targeted South Korean financial and cryptocurrency-related themes, including G20 financial meeting material and documents reportedly connected to the Bithumb theft. The HWP files contained malicious PostScript code that downloaded 32-bit or 64-bit next-stage payloads from tpddata.com paths, and the payload was identified as Manuscrypt. The samples communicated with C2 endpoints impersonating South Korean forum software, including anlway.com, apshenyihl.com, and ap8898.com PHP paths. The report also noted potentially related cryptocurrency phishing domains registered with the same phone number as malware delivery infrastructure, suggesting credential phishing may have accompanied malware delivery. The activity is significant for DPRK tracking because it connects Lazarus tradecraft to South Korean cryptocurrency and financial targets, while noting uncertainty about whether the same malware directly caused the Bithumb theft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d8af45210bf931bc5b03215ed30fb73… 2018-06-22 2022-07-31
HASH 06cfc6cda57fb5b67ee3eb0400dd5b97 2018-06-22 2019-07-03
DOMAIN tpddata.com 2018-06-22 2018-09-24
HASH 69ad5bd4b881d6d1fdb7b19939903e0b 2018-06-22 2018-08-07
HASH cf09201f02f2edb9c555942a2d6b01d4 2018-06-22 2018-08-07
HASH 5b1663d5eb565caccca188b6ff8a362… 2018-06-22 2018-06-22
HASH 3cde54dce88a4544bf5ffa36066a184… 2018-06-22 2018-06-22
HASH e76b3fd3e906ac23218b1fbd66fd29c… 2018-06-22 2018-06-22
HASH 2f4a958b148bef4be10780e8128860c… 2018-06-22 2018-06-22
HASH 596fbdf01557c3ec89b345c57ae5d9a… 2018-06-22 2018-06-22
HASH e98991cdd9ddd30adf490673c67a4f8… 2018-06-22 2018-06-22
HASH 7985af0a87780d27dc52c4f73c38de4… 2018-06-22 2018-06-22
HASH 58a97c2c731cdf045f26ccc7cba370b… 2018-06-22 2018-06-22
HASH 485f77e5d32de5dc05510743025a75a… 2018-06-22 2018-06-22
HASH 4838f85499e3c68415010d4f19e83e2… 2018-06-22 2018-06-22
HASH 927120588e6c4e5db5b5a1ea9914cd7… 2018-06-22 2018-06-22
HASH c10363059c57c52501c01f85e3bb435… 2018-06-22 2018-06-22
HASH afba8105793b635d4ed7febdae4b744… 2018-06-22 2018-06-22
HASH e498630abe9a91485ba42698a35c2a0… 2018-06-22 2018-06-22
HASH 2813c0ebcacdcf9052f71d51c81e9c5… 2018-06-22 2018-06-22
URL https://www.ap8898.com/include/… 2018-06-22 2018-06-22
URL http://mileage.krb.co.kr/common… 2018-06-22 2018-06-22
URL http://www.530hr.com/data/commo… 2018-06-22 2018-06-22
URL http://www.apshenyihl.com/inclu… 2018-06-22 2018-06-22
URL http://www.33cow.com/include/co… 2018-06-22 2018-06-22
URL http://www.shieldonline.co.za/s… 2018-06-22 2018-06-22
URL http://ansetech.co.kr/smartedit… 2018-06-22 2018-06-22
URL http://www.anlway.com/include/a… 2018-06-22 2018-06-22
URL http://www.97nb.net/include/arc… 2018-06-22 2018-06-22
URL http://www.marmarademo.com/incl… 2018-06-22 2018-06-22
URL https://www.apshenyihl.com/incl… 2018-06-22 2018-06-22
URL http://www.ap8898.com/include/a… 2018-06-22 2018-06-22
URL http://www.51up.com/ace/main.asp 2018-06-22 2018-06-22
URL http://168wangpi.com/include/ch… 2018-06-22 2018-06-22
URL http://www.028xmz.com/include/c… 2018-06-22 2018-06-22
URL http://www.paulkaren.com/synthp… 2018-06-22 2018-06-22
URL http://ando.co.kr/service/s_top… 2018-06-22 2018-06-22
URL https://www.anlway.com/include/… 2018-06-22 2018-06-22
DOMAIN bitfiniex.org 2018-06-22 2018-06-22
DOMAIN coinmaketcape.com 2018-06-22 2018-06-22
DOMAIN coinoen.org 2018-06-22 2018-06-22
HASH eb6275a24d047e3be05c2b4e5f50703d 2018-06-22 2018-06-22
HASH a6d1424e1c33ac7a95eb5b92b923c511 2018-06-22 2018-06-22
URL https://tpddata.com/skins/skin-… 2018-06-22 2018-06-22
URL https://tpddata.com/skins/skin-… 2018-06-22 2018-06-22
DOMAIN wifispeedcheck.net 2018-06-22 2018-06-22
DOMAIN itaddnet.com 2018-06-22 2018-06-22
DOMAIN 168wangpi.com 2018-03-07 2018-06-22
DOMAIN mileage.krb.co.kr 2018-03-07 2018-06-22
DOMAIN ansetech.co.kr 2018-03-07 2018-06-22
DOMAIN ando.co.kr 2018-03-07 2018-06-22

Related Actors

Related Reports

« Back