BLINDINGCAN - Malware Used by Lazarus -

2020-09-29 JPCERT

https://blogs.jpcert.or.jp/en/2020/09/BLINDINGCAN.html

Thumbnail for BLINDINGCAN - Malware Used by Lazarus -

JPCERT/CC analyzes BLINDINGCAN, a Lazarus/Hidden Cobra malware family loaded through a DLL after network intrusion. The malware stores encrypted configuration in the sample, a nearby file, or a registry value under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion, using XOR, AES, or RC4 with keys tied either to fixed values or host environment data. Its C2 protocol sends RC4-encrypted and Base64-encoded HTTP POST parameters chosen from common web field names, then receives XOR/RC4/Base64-encoded command data. BLINDINGCAN supports file and process operations, upload and download, service and disk enumeration, and arbitrary shell command execution, giving operators broad post-compromise control.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.sanlorenzoyacht.com… 2020-09-29 2021-02-25
URL https://www.automercado.co.cr/e… 2020-08-19 2021-02-25
URL https://www.curiofirenze.com/in… 2020-08-19 2021-02-25
HASH 8db272ea1100996a8a0ed0da3046109… 2020-09-29 2020-09-29
URL https://www.ne-ba.org/files/new… 2020-09-29 2020-09-29
HASH 58027c80c6502327863ddca28c31d35… 2020-08-19 2020-09-29

Related Actors

Related Reports

« Back