Panopticon-Project / panopticon-APT38

Creative Commons Attribution Share Alike 4.0 International
5 stars 3 forks source link

Images for LG #1

Open KadeMorton opened 6 years ago

KadeMorton commented 6 years ago

image Flow of PowerRatankba activity from victims to the Lazarus Group operators https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Timeline of campaigns ultimately related to PowerRatankba https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image https://twitter.com/LeoAW/status/881761293874610176

KadeMorton commented 6 years ago

image Script output showing PowerSpritz PowerShell encoded and decoded command https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image PowerSpritz retrieving Base64-encoded PowerRatankba https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Malicious LNK AppLocker bypass to retrieve payload https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image CHM lures utilized in attempts to deliver PowerRatankba https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Malicious code embedded in CHM to download a VBScript PowerRatankba downloader https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image BITSAdmin retrieving malicious payload over HTTP https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image PowerShell utilized in CHM to retrieve PowerRatankba downloader VBS https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Leftover code in 5_6283065828631904327.chm https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Obfuscated falconcoin.js https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Deobfuscated falconcoin.js revealing PowerRatankba and decoy PDF URLs https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Decoys downloaded or sent along with PowerRatankba JavaScript downloaders https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Spearphishing email spoofed sender and subject

image IRS themed Word document PowerRatankba downloader https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image IRS-themed malicious document macro https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Malicious Bithumb Excel spreadsheet with English option shown, with stolen branding

image “About Bithumb.pdf decoy” document inside Bithumb.zip archive, with stolen branding https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf

KadeMorton commented 6 years ago

image Base64 encoded PowerRatankba downloader embedded in bithumb.xls