ROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE
2019-12-11 • Cybereason •
Cybereason reported targeted campaigns against financial, manufacturing, and retail organizations in the United States and Europe that began with phishing and TrickBot infection before progressing into interactive intrusion activity. The phishing lure used a Google Docs link to deliver a signed TrickBot downloader disguised as a Microsoft Word document named like an annual bonus report, then injected TrickBot into svchost.exe. The attackers profiled infected hosts, contacted C2 infrastructure including TOR-related domains, stole browser and application credentials, and used Windows utilities and PowerShell for reconnaissance and lateral movement. On selected high-value targets, the activity deployed Anchor_DNS and a newly documented Anchor variant, backdoors described as tightly connected to TrickBot and used selectively. The excerpt does not provide DPRK attribution, so the supported finding is a TrickBot/Anchor intrusion pattern with potential outcomes including POS compromise, ransomware, or theft of sensitive financial data.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | api.ipify.org | 2019-12-11 | 2026-03-17 |
| HASH | 5f1ad1787106de9725005d8da33d815… | 2019-12-11 | 2019-12-11 |
| HASH | 9ebb541dcb24d564448a6f5e00c613b… | 2019-12-11 | 2019-12-11 |
| HASH | 55c60b5d13499341d72f5a34c632cfd9 | 2019-12-11 | 2019-12-11 |
| HASH | f3683a0c12154e8bf44d9d942db3eac… | 2019-12-11 | 2019-12-11 |
| HASH | 46c595e580719a4c54f55b4041f81d6… | 2019-12-11 | 2019-12-11 |
| HASH | b388243bf5899c99091ac2df13339f1… | 2019-12-11 | 2019-12-11 |
| HASH | d4cb942aa18eff519dcbcae88a0a99fb | 2019-12-11 | 2019-12-11 |
| HASH | 6e8516ca48318fb2904e2027b5350b26 | 2019-12-11 | 2019-12-11 |
| HASH | 3ed09498214d93c9ec14a15286546d2… | 2019-12-11 | 2019-12-11 |
| HASH | e75983b073ff0632e35e237f6622466… | 2019-12-11 | 2019-12-11 |
| HASH | bd26238fb7d7e16ea79073d882bba00… | 2019-12-11 | 2019-12-11 |
| HASH | 4bba60ff11f8b150b004960c658ad74… | 2019-12-11 | 2019-12-11 |
| HASH | e5dc7c8bfa285b61dda1618f0ade9c2… | 2019-12-11 | 2019-12-11 |
| DOMAIN | chishir.com | 2019-12-11 | 2019-12-11 |
| DOMAIN | northracing.net | 2019-12-11 | 2019-12-11 |
| IPv4 | 23.95.97.59 | 2019-12-11 | 2019-12-11 |
| IPv4 | 91.12.89.129 | 2019-12-11 | 2019-12-11 |
| IPv4 | 199.217.115.53 | 2019-12-11 | 2019-12-11 |