APT-C-26(Lazarus)组织使用EarlyRat的攻击活动分析

2023-09-12 • Qihoo360 • Analysis of attack activities of APT-C-26 (Lazarus) organization using EarlyRat •

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247493393&idx=1&sn=027208d09492e20bb0c0985afd548927&chksm=f9c1d418ceb65d0e3186ff8d646c23f530dd91f92b223ea27fd20184745a8291d0ab1d28fbb6&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-26(Lazarus)组织使用EarlyRat的攻击活动分析

360 Advanced Threat Research linked APT-C-26/Lazarus and its Andariel subgroup to EarlyRat activity delivered through Skype links to malicious compressed files and macro-enabled lure documents. The macro dropped an EarlyRat binary into the Windows startup folder as WHealthScanner.exe, giving the operator persistence and the ability to collect host information and run commands. The analysis describes EarlyRat string decryption, host-ID generation, encrypted system profiling, and command execution, including systeminfo, netstat, ipconfig, and tasklist collection. The report correlates a C2 address, 40.121.90.194/help.php, with Cisco and Kaspersky reporting on Lazarus operations against energy suppliers and Log4j-based deployment in early 2022.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9a5504dcfb7e664259bfa58c46cfd33… 2023-05-16 2024-07-25
IPv4 74.124.228.148 2023-09-12 2024-06-13
HASH 303bc0f4742c61166d05f7a14a25b3c… 2023-09-12 2023-09-12
HASH 83388741cb6e6ee7341ae00cb9ab92c… 2023-09-12 2023-09-12
HASH 22e184b0de989255acadad08c9175d9… 2023-09-12 2023-09-12
HASH faba4114ada285987d4f7c771f096e0… 2023-09-12 2023-09-12
HASH 9b65da2aa008e2208406e5a87d2c976… 2023-09-12 2023-09-12
HASH df0c7bb88e3c67d849d78d13cee3067… 2023-02-09 2023-09-12
IPv4 40.121.90.194 2022-09-08 2023-09-12

Related Actors

First seen: Jul 2017
Last seen: Sep 2026

Related Reports

« Back