Hunting Lazarus: Expanding Indicators with Historic DNS
2024-07-15 • Validin •
https://www.validin.com/blog/hunting-lazarus-dns-history-host-responses/
Validin used historic DNS, host-response data, and certificate pivots to expand from roomconnect[.]online into additional infrastructure assessed as Lazarus Group-related. The research focused on meeting-themed domains, wildcarded subdomains, shared IP resolutions, certificate SHA1 8edc64bd3deaa4397af5453aee893fa6704dfabf, registration timing, and overlap with previously known Lazarus-associated indicators such as instant-patch[.]online. The pivots produced higher-confidence domains including virtual-collab[.]online, meeting-hub[.]online, meeting-central[.]online, and broader sets of meeting and document-sharing themed domains consistent with Lazarus phishing and impersonation tradecraft. Validin reported 29 apex domains and 8 IP addresses as currently or recently associated with the activity based on those infrastructure relationships.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 104.168.165.203 | 2024-07-15 | 2025-02-12 |
| IPv4 | 104.168.157.45 | 2024-07-15 | 2025-02-12 |
| HASH | 8edc64bd3deaa4397af5453aee893fa… | 2024-07-15 | 2024-07-15 |
| DOMAIN | internal-meet.xyz | 2024-07-15 | 2024-07-15 |
| IPv4 | 108.174.194.10 | 2024-07-15 | 2024-07-15 |
| IPv4 | 104.168.203.159 | 2024-07-15 | 2024-07-15 |
| IPv4 | 104.168.165.173 | 2024-07-15 | 2024-07-15 |
| IPv4 | 104.168.165.165 | 2024-07-15 | 2024-07-15 |
| IPv4 | 104.168.203.161 | 2024-07-15 | 2024-07-15 |
| IPv4 | 104.168.137.21 | 2023-12-06 | 2024-07-15 |