라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습

2019-03-27 • ESTSecurity • Lazarus Group counterattacks APT targeting Israeli military companies •

https://blog.alyac.co.kr/2219

Thumbnail for 라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습

ESRC investigated reporting that Lazarus-linked operators targeted Israeli defense and aerospace-related organizations through spear-phishing, including Israel Military Industries and Ashot Ashkelon Industries. The lure impersonated a SysAid software update in Hebrew and delivered a RAR file that internally used the ACE format and CVE-2018-20250 to place a malicious executable in the Windows Startup path. The payload, ekrnview.exe, was a 64-bit Windows executable that queried host information, checked Windows product data, and contacted hardcoded C2 endpoints including alahbabgroup.com, 103.225.168.159, khuyay.org, and 47.91.56.21. The same 103.225.168.159 address appeared in a crafted LNK icon path, and one C2 server exposed directory listing and a B374k web shell, giving defenders infrastructure and tooling artifacts to compare with related Middle East WinRAR exploit activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2eb447785e5b35c42d842706d593a90… 2019-03-26 2020-03-09
HASH 507cc26afa06c0587f0aa51d6986168… 2019-03-27 2019-03-27
HASH 3a6cc90db63a6d09721886b6e3f795e… 2019-03-27 2019-03-27
URL http://www.alahbabgroup.com/bak… 2019-03-27 2019-03-27
URL http://www.khuyay.org/odin_back… 2019-03-27 2019-03-27
IPv4 198.96.95.58 2019-03-27 2019-03-27
IPv4 170.239.84.243 2019-03-27 2019-03-27
IPv4 47.91.56.21 2019-03-26 2019-03-27
IPv4 103.225.168.159 2019-03-26 2019-03-27

Related Actors

Related Reports

« Back