BLINDINGCAN - Malware Used by Lazarus -
2020-09-29 • JPCERT •
JPCERT/CC analyzes BLINDINGCAN, a Lazarus/Hidden Cobra malware family loaded through a DLL after network intrusion. The malware stores encrypted configuration in the sample, a nearby file, or a registry value under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion, using XOR, AES, or RC4 with keys tied either to fixed values or host environment data. Its C2 protocol sends RC4-encrypted and Base64-encoded HTTP POST parameters chosen from common web field names, then receives XOR/RC4/Base64-encoded command data. BLINDINGCAN supports file and process operations, upload and download, service and disk enumeration, and arbitrary shell command execution, giving operators broad post-compromise control.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.sanlorenzoyacht.com… | 2020-09-29 | 2021-02-25 |
| URL | https://www.automercado.co.cr/e… | 2020-08-19 | 2021-02-25 |
| URL | https://www.curiofirenze.com/in… | 2020-08-19 | 2021-02-25 |
| HASH | 8db272ea1100996a8a0ed0da3046109… | 2020-09-29 | 2020-09-29 |
| URL | https://www.ne-ba.org/files/new… | 2020-09-29 | 2020-09-29 |
| HASH | 58027c80c6502327863ddca28c31d35… | 2020-08-19 | 2020-09-29 |