Commonly Known Tools Used by Lazarus

2021-01-20 JPCERT

https://blogs.jpcert.or.jp/en/2021/01/Lazarus_tools.html

Thumbnail for Commonly Known Tools Used by Lazarus

JPCERT documented commonly available tools observed in Lazarus intrusions, emphasizing that the group supplements malware with legitimate utilities after gaining access. For lateral movement and network discovery, the excerpt names AdFind for Active Directory enumeration, SMBMap for accessible SMB shares, and Responder-Windows for LLMNR, NBT-NS, and WPAD spoofing. For credential and data theft, it highlights XenArmor password recovery tools and WinRAR, while noting that Lazarus malware can also archive data with zlib. Additional tools such as TightVNC Viewer, ProcDump, tcpdump, and wget-like Windows utilities show how dual-use software can support remote access, LSASS memory dumping, packet capture, and post-compromise operations that may evade antivirus detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 30b234e74f9abe72eefde585c39300c… 2021-01-20 2021-01-20
HASH ea139458b4e88736a3d48e81569178f… 2021-01-20 2021-01-20
HASH 5d1660a53aaf824739d82f703ed5800… 2021-01-20 2021-01-20
HASH 4b7de800ccaedee8a0edd63d4273a20… 2021-01-20 2021-01-20
HASH 1e0480e0e81d5af360518dff65923b3… 2021-01-20 2021-01-20
HASH cf0121cd61990fd3f436bda2b2aff03… 2021-01-20 2021-01-20
HASH f4c8369e4de1f12cc5a71eb5586b38f… 2021-01-20 2021-01-20
HASH cf02b7614fea863672ccbed7701e5b5… 2021-01-20 2021-01-20
HASH da4ad44e8185e561354d29c153c0804… 2021-01-20 2021-01-20
HASH 7dccc776c464a593036c597706016b2… 2021-01-20 2021-01-20
HASH a7ad23ee318852f76884b1b1f332ad5… 2021-01-20 2021-01-20
HASH b1102ed4bca6dae6f2f498ade2f73f7… 2021-01-20 2021-01-20
HASH 2cd844c7a4f3c51cb7216e9ad31d825… 2021-01-20 2021-01-20
HASH cfd201ede3ebc0deb0031983b2bda9f… 2021-01-20 2021-01-20
HASH 65ddf061178ad68e85a2426caf9cb85… 2021-01-20 2021-01-20
HASH 85703efd4ba5b691d6b052402c2e5de… 2021-01-20 2021-01-20
HASH c0e27b7f6698327ff63b03fccc0e45e… 2021-01-20 2021-01-20
HASH 47d121087c05568fe90a25ef921f9e3… 2021-01-20 2021-01-20
URL http://www.joeware.net/freetool… 2021-01-20 2021-01-20
DOMAIN xenarmor.com 2021-01-20 2021-01-20

Related Actors

Related Reports

« Back