Lazarus group leverages Covid themed HWP Document
2020-05-09 • dinu135dk •
https://medium.com/@dinu135dk/lazarus-group-leverages-covid-themed-hwp-document-dde6b80d51eb
The excerpt describes a Lazarus campaign using a COVID-themed HWP document targeting South Korea, including a Jeollanam-do coronavirus inquiry lure. OSINT analysis found the executable was downloaded from sofa.rs and matched detection logic for a reflective loader. The executable is described with a victim-selection kill switch, sandbox and debugger evasion, execution-timing checks, and IsDebuggerPresent use. Mapped behaviors include WMI and API execution, application shimming, masquerading, packing, input capture, discovery activity, remote file copy, clipboard collection, encrypted exfiltration, and standard cryptographic protocol command and control. The report provides MD5 indicators and YARA-style reflective-loader strings that defenders can use for triage and detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | mbrainingevents.com | 2020-04-02 | 2020-05-29 |
| YARA | ReflectiveLoader | 2020-05-09 | 2020-05-09 |
| HASH | 186aa05bfe4739274c3c258be4a5a160 | 2020-05-09 | 2020-05-09 |
| IPv4 | 185.62.56.131 | 2020-05-09 | 2020-05-09 |
| HASH | fe2d05365f059d48fd972c79afeee682 | 2020-04-15 | 2020-05-09 |
| HASH | 8451be72b75a38516e7ba7972729909e | 2020-04-02 | 2020-05-09 |