북한 해킹 단체 라자루스(Lazarus) 추측이 되는 악성코드-WerFault.lnk(2024.8.19)

2024-08-28 Sakai Malware Suspected to Be from the North Korean Hacking Group Lazarus - WerFault.lnk (2024.8.19)

https://wezard4u.tistory.com/429263

Thumbnail for 북한 해킹 단체 라자루스(Lazarus) 추측이 되는 악성코드-WerFault.lnk(2024.8.19)

A Korean malware analysis describes a WerFault.lnk sample assessed by the author as likely tied to a North Korean APT, while the exact cluster remains uncertain among Lazarus, Kimsuky, Konni, or another DPRK-linked group. The LNK copies the legitimate Windows WerFault.exe to %temp%, runs hidden PowerShell, finds a same-sized LNK file, XOR-decodes embedded bytes with 0x71, writes the payload as %temp%\faultrep.dll, and launches the copied WerFault.exe for side-loading. The extracted DLL checks for VirtualBox, VMware, and Xen-related processes such as vboxservice.exe, vmtoolsd.exe, vmware.exe, and xenservice.exe, indicating anti-analysis logic. The source also lists hashes for the LNK and DLL and notes broad antivirus detection of the DLL as Kryptik, Ulise, Wacatac, Rozena, or generic Trojan malware.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bdf6730d5c52821e237a7ceb47d8838d 2024-08-28 2024-08-28
HASH ac7772803e0f65522f43357cb31b0b0… 2024-08-28 2024-08-28
HASH 0dda91a21b6f6536715eb83f21c75451 2024-08-28 2024-08-28
HASH 0b1d881b010b2230a5ba9e5d9a0f0d3… 2024-08-28 2024-08-28

Related Actors

Related Reports

« Back