In depth analysis of Lazarus validator

2020-05-15 Malwarelab

https://blog.malwarelab.pl/posts/lazarus_validator/

Thumbnail for In depth analysis of Lazarus validator

MalwareLab analyzed a Lazarus-attributed validator from malicious Word documents impersonating Lockheed Martin and linked the samples to a broader campaign probably aimed at military contractors doing business with South Korea. The documents embedded two DLLs and an additional lure document so victims saw a fuller decoy rather than only a first page, reducing suspicion during execution. The validator used macro-supplied parameters, deleted the infection document path, established autostart persistence, and in some variants unpacked an intermediary DLL before contacting C2 for the next-stage payload. Its configuration used AES keys derived from an MD5 value, included the C2 URL https://www.astedams.it/include/inc-elenco-offerter.asp, collected drive information, and exchanged compressed and base64-encoded binary blobs before loading a received PE in memory. Attribution is explicitly tied to prior reporting that described the same infection scheme and DLL family, rather than independent attribution from the sample alone.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8fc7b0764541225e5505fa93a7376df4 2020-05-15 2023-04-12
HASH cd5357d1045948ba62710ad8128ae282 2020-05-15 2023-04-12
HASH 1bd0ca304cdecfa3bd4342b261285a72 2020-05-15 2023-04-12
HASH 0071b20d27a24ae1e474145b8efc9718 2020-05-15 2023-04-12
HASH 265f407a157ab0ed017dd18cae0352ae 2020-05-15 2023-04-12
HASH c0a8483b836efdbae190cc069129d5c3 2020-05-15 2023-04-12
HASH 25b37c971fd7e9e50e45691aa86e5f0a 2020-05-15 2023-04-12
HASH 92657b98c2b4ee4e8fa1b83921003c74 2020-05-15 2023-04-12
HASH 59cb8474930ae7ea45b626443e01b66d 2020-05-15 2023-04-12
HASH 14d79cd918b4f610c1a6d43cadeeff7b 2020-05-15 2023-04-12
HASH 075fba0c098d86d9f22b8ea8c3033207 2020-05-15 2023-04-12
HASH d1c652b4192857cb08907f0ba1790976 2020-05-15 2023-04-12
HASH 78d42cedb0c012c62ef5be620c200d43 2020-05-15 2023-04-12
HASH 1f254dd0b85edd7e11339681979e3ad6 2020-05-15 2023-04-12
HASH f4b55da7870e9ecd5f3f565f40490996 2020-04-30 2023-04-12
HASH 2b02465b65024336a9e15d7f34c1f5d9 2020-04-30 2023-04-12
HASH 65df11dea0c1d0f0304b376787e65ccb 2020-04-30 2023-04-12
HASH 2efbe6901fc3f479bc32aaf13ce8cf12 2020-04-30 2023-04-12
HASH f6d6f3580160cd29b285edf7d0c647ce 2020-04-30 2023-04-12
HASH 11fdc0be9d85b4ff1faf5ca33cc272ed 2020-04-30 2023-04-12
HASH 7228705813d5bc6c6a62fc53ac019344 2020-05-15 2021-12-21
HASH 1b0c82e71a53300c969da61b085c8ce… 2020-05-15 2020-07-29
HASH 66e5371c3da7dc9a80fb4c0fabfa23a… 2020-05-15 2020-07-29
HASH bff4d04caeaf8472283906765df3442… 2020-05-15 2020-07-29
HASH b76b6bbda8703fa801898f843692ec1… 2020-05-15 2020-07-29
HASH 48b8486979973656a15ca902b7bb973… 2020-05-15 2020-07-29
HASH d7ef8935437d61c975feb2bd826d018… 2020-05-15 2020-07-29
HASH 37a3c01bb5eaf7ecbcfbfde1aab8489… 2020-05-15 2020-07-29
URL http://www.elite4print.com/admi… 2020-05-15 2020-07-29
URL https://www.sanlorenzoyacht.com… 2020-05-15 2020-07-29
URL https://www.astedams.it/uploads… 2020-05-08 2020-07-29
URL https://www.sanlorenzoyacht.com… 2020-04-30 2020-07-29
YARA apt_NK_Lazarus_DllImplat_cfg_de… 2020-05-15 2020-05-15
YARA apt_NK_Lazarus_DllImplat_cmd_li… 2020-05-15 2020-05-15
HASH 7fdfc719935d938651f45aafef3cd2e… 2020-05-15 2020-05-15
HASH d79bfa19e4d32692030d15c2767beb8… 2020-05-15 2020-05-15
HASH 1076b25d5fa5cccdddcaf3f788789ae… 2020-05-15 2020-05-15
HASH 3aa8eddf26f5944a24dfeb57c9f49a17 2020-05-15 2020-05-15
HASH 0f0b242fb5d73d08b856bc43432b350… 2020-05-15 2020-05-15
HASH 7f39a52fc6a51b5dd3830064c63f9d4… 2020-05-15 2020-05-15
HASH cf44576adcfc51a062457398797f99e… 2020-05-15 2020-05-15
HASH 141931bf718c5c4d3931f64b04e2112… 2020-05-15 2020-05-15
HASH 6590f66d6afe155b1109e81e2c36ece… 2020-05-15 2020-05-15
HASH b493f37ee0fddb1d832ddacaaf417029 2020-05-15 2020-05-15
HASH 805183c19f4bffca871fb344247bd5d… 2020-05-15 2020-05-15
HASH 2627b7c827404ee49271bfc6bb152e5… 2020-05-15 2020-05-15
HASH 454734dca530d54c4e8f543bdd33b5e… 2020-05-15 2020-05-15
HASH 7b5089c2bea3ec4aa98c5cdf69dac21… 2020-05-15 2020-05-15
HASH 23d73fc8f10588944d8dc2073ce6af6… 2020-05-15 2020-05-15
HASH 3c5c1a7e7efe4eee3b7650167c664f7… 2020-05-15 2020-05-15
HASH 223e954fd67c6cf75c3a6f987b94784b 2020-05-15 2020-05-15
HASH a8647a04563b746b1d8d4cdd67616cb… 2020-05-15 2020-05-15
HASH cb38822697af45210d2759889c2eb2b… 2020-05-15 2020-05-15
HASH 21515fd6e6eb994defb589b4d0d9d95… 2020-05-15 2020-05-15
HASH 59fab92d51c50467c1356080e6a5dead 2020-05-15 2020-05-15
HASH 69e50a20ea6be94e4336ba8cea3c438… 2020-05-15 2020-05-15
HASH 074c02f7f5badd5c94d840c1e2ae9f72 2020-05-15 2020-05-15
HASH a769b39d0c80d1a035dd51efa28b092… 2020-05-15 2020-05-15
HASH f3e4947e32c6b1d0303b342a74426d4… 2020-05-15 2020-05-15
URL https://www.curiofirenze.com/ne… 2020-05-15 2020-05-15
URL http://www.astedams.it/include/… 2020-05-15 2020-05-15
URL https://www.astedams.it/uploads… 2020-05-08 2020-05-15
HASH 26a2fa7b45a455c311fd57875d8231c… 2019-11-05 2020-05-15
HASH ec254c40abff00b104a949f07b7b642… 2019-11-05 2020-05-15

Related Actors

Related Reports

« Back