라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습
2019-03-27 • ESTSecurity • Lazarus Group counterattacks APT targeting Israeli military companies •
ESRC investigated reporting that Lazarus-linked operators targeted Israeli defense and aerospace-related organizations through spear-phishing, including Israel Military Industries and Ashot Ashkelon Industries. The lure impersonated a SysAid software update in Hebrew and delivered a RAR file that internally used the ACE format and CVE-2018-20250 to place a malicious executable in the Windows Startup path. The payload, ekrnview.exe, was a 64-bit Windows executable that queried host information, checked Windows product data, and contacted hardcoded C2 endpoints including alahbabgroup.com, 103.225.168.159, khuyay.org, and 47.91.56.21. The same 103.225.168.159 address appeared in a crafted LNK icon path, and one C2 server exposed directory listing and a B374k web shell, giving defenders infrastructure and tooling artifacts to compare with related Middle East WinRAR exploit activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2eb447785e5b35c42d842706d593a90… | 2019-03-26 | 2020-03-09 |
| HASH | 507cc26afa06c0587f0aa51d6986168… | 2019-03-27 | 2019-03-27 |
| HASH | 3a6cc90db63a6d09721886b6e3f795e… | 2019-03-27 | 2019-03-27 |
| URL | http://www.alahbabgroup.com/bak… | 2019-03-27 | 2019-03-27 |
| URL | http://www.khuyay.org/odin_back… | 2019-03-27 | 2019-03-27 |
| IPv4 | 198.96.95.58 | 2019-03-27 | 2019-03-27 |
| IPv4 | 170.239.84.243 | 2019-03-27 | 2019-03-27 |
| IPv4 | 47.91.56.21 | 2019-03-26 | 2019-03-27 |
| IPv4 | 103.225.168.159 | 2019-03-26 | 2019-03-27 |