Operation Flash Cobra

2020-05-05 Strangereal Intel

https://github.com/StrangerealIntel/CyberThreatIntel/blob/master/North%20Korea/APT/Lazarus/2020-05-05/Analysis.md

Operation Flash Cobra is analyzed as Lazarus activity that begins with a malicious document using remote template injection to retrieve and execute the next-stage DOTM macro. The macro decodes embedded content, extracts an architecture-specific DLL and lure document, and stores the DLL under a OneNote-looking path in the user’s AppData Local Microsoft directory. Execution is tied to the document auto-open flow, which calls exported DLL functionality with victim-specific identifiers and displays the lure document while the malicious component runs. The excerpt further notes persistence-related identifiers, rundll32-style DLL execution, thread creation, and sqlite3.dll functionality apparently used to parse SQLite databases and extract information.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://schemas.openxmlformats.o… 2020-03-20 2023-06-06
DOMAIN elite4print.com 2020-04-28 2022-09-29
URL https://od.lk/d/MzBfMjA1Njc0ODd… 2020-04-30 2020-07-29
HASH 3bfa9cc97da10598521b342961df8f5… 2020-05-05 2020-05-05

Related Actors

Related Reports

« Back