Rewterz Threat Alert – Lazarus APT Group, Attacked as Identity Document
July 16, 2019Rewterz Threat Alert – Continuing Lazarus Attacks – NukeSped Sample
July 17, 2019Rewterz Threat Alert – Lazarus APT Group, Attacked as Identity Document
July 16, 2019Rewterz Threat Alert – Continuing Lazarus Attacks – NukeSped Sample
July 17, 2019Severity
High
Analysis Summary
Android malware that contains a backdoor file in the executable and linkable format (ELF). The ELF file is similar to several executables that have been reported to belong to the Lazarus cybercrime group. The malware poses as a legitimate APK, available from Google Play, for reading the Bible in Korean. The legit app has been installed more than 1,300 times. The malware has never appeared on Google Play.
Impact
Device acts like a bot
Indicators of Compromise
URLs
- http[:]//103[.]53[.]176[.]145[:]8080/ServiceDeskPlus/products[.]do
- http[:]//111[.]68[.]126[.]155[:]8080/ServiceDeskPlus/products[.]do
- http[:]//137[.]117[.]57[.]244[:]8080/ServiceDeskPlus/products[.]do
- http[:]//chanbang[.]co[.]kr/board/check[.]asp
- http[:]//chanbang[.]co[.]kr/family/check[.]asp
- http[:]//chanbang[.]co[.]kr/gonggu/upload[.]asp
- http[:]//difa[.]or[.]kr/common/asp/inc_Comn[.]asp
- http[:]//edenenc[.]co[.]kr/Report/RptMyReport[.]asp
- http[:]//egreenland[.]co[.]kr/cheditor2/example/newpost[.]asp
- http[:]//hanbook[.]co[.]kr/partnershop/hanmail_ep[.]asp
- http[:]//img[.]kindermom[.]co[.]kr/frameart/print/footer[.]mov
- http[:]//kgsa1015[.]co[.]kr/upload/member/member[.]asp
- http[:]//rodaxsankyokorea[.]com/upload/favicon/favicon[.]asp
- http[:]//www[.]kgsa1015[.]co[.]kr/upload/member/member[.]asp
- http[:]//www[.]sinokor-eng[.]com/sub/sub01_09[.]asp
Malware Hash (MD5/SHA1/SH256)
- 12518eaa24d405debd014863112a3c00a652f3416df27c424310520a8f55b2ec
- 1a9714fe84d62ae23b9eb439dbea6562e424e1c20f433a4f8338347bee2fd65e
- 20e6391cf3598a517467cfbc5d327a7bb1248313983cba2b56fd01f8e88bb6b9
- 21c7180c568bf115a0784629a8e5575103007f66ab2b964ab1d7f3290f5ab370
- 3fb44f4698168b53642c8a4a8ba32ee8
- 5621c89102d84f4a335218cb84a94852
- 59404af2d92c53ad1ee9e21b252c07c77dcba810b248a79d6ae989b1ff63c7d6
- 65c27af540d1a3f7b74db62e85adcdf9c686f70d1263e89a8d2545c6b7f49154
- 69ceb2c4770262e75cf7ef7f48c222dad63690e354809d528ad2a3de7a84f794
- 7ad49a8df0fb1b9238dc7e3ec7c1bc274ca8e29e154abf3a4acff15506423794
- 7c8d3ca5c540912590eec20b5a55dac979ccc55da9eefccbe65ee0e84122e93d
- 91f8c1f11227ee1d71f096fd97501c17a1361d71b81c3e16bcdabad52bfa5d9f
- 97bfb4528facc9bd1464d70744fa3f328e7269934d919b54c505ea8d461c7b4e
- 98435958d61012e842039a5d572908a52017e1367c4e1f61bf0812dcfbcac126
- 9deb8bb7c8a8eb012761a05a67aa2c72e1ef310c9395aaa3293869c5314676cf
- b6682cab65d3243b5b75efb7279dbf49491957484780f2ba0a87632cc0e25642
- b8b5d82eb25815dd3685630af9e9b0938bccecb3a89ce0ad94324b12d25983f0
- b9d9b2e39247744723f72f63888deb191eafa3ffa137a903a474eda5c0c335cf
- bfeef232cc83af4a3afd262bddc1b9fbb6e829ac1980461003ea551051808268
- e477c8195fcbb95e7764027a9fb4aabeae475879b809d2e542cfd84ca34c1b5c
- ecb6603a8cd1354c9be236a3c3e7bf498576ee71f7c5d0a810cb77e1138139ec
- fe92a44d726b43927f51418ce09ce9731c7a46a0dd6d9e4b46af34fdf99009ef
Remediation
- Always keep your mobile security application updated to the latest version.
- Never install applications from unverified sources.