Another Lazarus Injector
2019-10-02 • Norfolk •
The follow-up Lazarus Injector analysis covers a signed malware tool uploaded to VirusTotal that appears related to earlier Lazarus tooling but behaves differently from the first injector. The file expects command-line parameters for operational mode and target process ID, supporting injection or ejection behavior rather than simply loading a supplied payload into Explorer. The author notes strong resemblance to tooling described in a FASTCash AIX malware report, suggesting a Windows counterpart for similar operational needs. The post provides hashes, signing context, and behavior details for detecting Lazarus injection utilities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 89081f2e14e9266de8c042629b764926 | 2019-10-02 | 2020-08-05 |
| HASH | 39cbad3b2aac6298537a85f0463453d… | 2019-10-02 | 2020-03-09 |
| HASH | 730c1b9e950932736fc4b02cbdb4e4e… | 2019-10-02 | 2019-10-02 |
Related Actors
Related Reports
2019-10-24 •
80% Match
#Lazarus
Shares tag: Lazarus • Published within a month
2019-10-17 •
80% Match
Let's Learn: Dissecting Lazarus Windows x86 Loader Involved in Crypto Trading App Distribution: "snowman" & ADVObfuscator
Vkremez
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Same author: Norfolk
Shares tag: Lazarus • Shares 1 IOC
Shares tag: Lazarus
Shares tag: Lazarus