Paleontology: The Unknown Origins of Lazarus malware
2018-10-31 • Intezer •
https://www.intezer.com/paleontology-the-unknown-origins-of-lazarus-malware/
Intezer traces part of Lazarus malware lineage to CasperPhpTrojan, an open-source RAT published on a Chinese project site, after VirusTotal samples from 2016 matched Lazarus-related code signatures. The analysis found overlap with RedGambler code genes, an internal module name DllTroy.dll, and reused strings associated with Operation Troy and Prioxer. By compiling and comparing CasperPhpTrojan source against Lazarus binaries, Intezer identified shared implementation patterns such as HTTP header construction and GetProcAddress/LoadLibrary usage. The report includes hashes and infrastructure such as ready-jetkorea[.]com and plsong[.]com URLs that can support further pivoting. The finding matters because it reframes some Lazarus code reuse as possible adaptation of public RAT source code rather than exclusively original DPRK-developed tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | pudn.com | 2018-10-31 | 2020-08-05 |
| HASH | d1cf03fbcb6471d44b914c272082158… | 2018-10-31 | 2018-10-31 |
| HASH | f4b7b36e9c940937748d5bba3beb82b… | 2018-10-31 | 2018-10-31 |
| HASH | 4915f53221dc7786710a7a82a9cb00c… | 2018-10-31 | 2018-10-31 |
| HASH | c62ec66e45098d2c41bfd7a674a5f76… | 2018-10-31 | 2018-10-31 |
| HASH | 458ffcc41959599f8dab1fd4366c9a5… | 2018-10-31 | 2018-10-31 |
| HASH | 6724c041fe0df61a619006bf1df4a75… | 2018-10-31 | 2018-10-31 |
| HASH | ec73fe2ecc2e0425e4aeb1f01581b50… | 2018-10-31 | 2018-10-31 |
| HASH | 1b6a1320fba00dd2e56e35cf6f11f94… | 2018-10-31 | 2018-10-31 |
| HASH | 926a2e8c2baa90d504d48c0d50ca73e… | 2018-10-31 | 2018-10-31 |
| HASH | 068b89e2ec5655d006f2788ea328e5f… | 2018-10-31 | 2018-10-31 |
| URL | http://ready-jetkorea.com/data/… | 2018-10-31 | 2018-10-31 |
| URL | http://plsong.com/xe/addons/cou… | 2018-10-31 | 2018-10-31 |
| DOMAIN | ready-jetkorea.com | 2018-10-31 | 2018-10-31 |
| DOMAIN | plsong.com | 2018-10-31 | 2018-10-31 |