ROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE

2019-12-11 Cybereason

https://www.cybereason.com/blog/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware

Thumbnail for ROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE

Cybereason reported targeted campaigns against financial, manufacturing, and retail organizations in the United States and Europe that began with phishing and TrickBot infection before progressing into interactive intrusion activity. The phishing lure used a Google Docs link to deliver a signed TrickBot downloader disguised as a Microsoft Word document named like an annual bonus report, then injected TrickBot into svchost.exe. The attackers profiled infected hosts, contacted C2 infrastructure including TOR-related domains, stole browser and application credentials, and used Windows utilities and PowerShell for reconnaissance and lateral movement. On selected high-value targets, the activity deployed Anchor_DNS and a newly documented Anchor variant, backdoors described as tightly connected to TrickBot and used selectively. The excerpt does not provide DPRK attribution, so the supported finding is a TrickBot/Anchor intrusion pattern with potential outcomes including POS compromise, ransomware, or theft of sensitive financial data.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN api.ipify.org 2019-12-11 2026-03-17
HASH 5f1ad1787106de9725005d8da33d815… 2019-12-11 2019-12-11
HASH 9ebb541dcb24d564448a6f5e00c613b… 2019-12-11 2019-12-11
HASH 55c60b5d13499341d72f5a34c632cfd9 2019-12-11 2019-12-11
HASH f3683a0c12154e8bf44d9d942db3eac… 2019-12-11 2019-12-11
HASH 46c595e580719a4c54f55b4041f81d6… 2019-12-11 2019-12-11
HASH b388243bf5899c99091ac2df13339f1… 2019-12-11 2019-12-11
HASH d4cb942aa18eff519dcbcae88a0a99fb 2019-12-11 2019-12-11
HASH 6e8516ca48318fb2904e2027b5350b26 2019-12-11 2019-12-11
HASH 3ed09498214d93c9ec14a15286546d2… 2019-12-11 2019-12-11
HASH e75983b073ff0632e35e237f6622466… 2019-12-11 2019-12-11
HASH bd26238fb7d7e16ea79073d882bba00… 2019-12-11 2019-12-11
HASH 4bba60ff11f8b150b004960c658ad74… 2019-12-11 2019-12-11
HASH e5dc7c8bfa285b61dda1618f0ade9c2… 2019-12-11 2019-12-11
DOMAIN chishir.com 2019-12-11 2019-12-11
DOMAIN northracing.net 2019-12-11 2019-12-11
IPv4 23.95.97.59 2019-12-11 2019-12-11
IPv4 91.12.89.129 2019-12-11 2019-12-11
IPv4 199.217.115.53 2019-12-11 2019-12-11

Related Reports

« Back