THE LAZARUS’ GAZE TO THE WORLD: WHAT IS BEHIND THE FIRST STONE ?
2019-11-05 • Telsy •
https://web.archive.org/web/20200605214110/https://blog.telsy.com/lazarus-gate/
Telsy TRT analyzed a likely Lazarus operation that began from a spoofed email delivering a malicious document to an Italian banking and financial institution. The document carried architecture-specific first-stage payloads and dropped a library under a Microsoft ThumbNail path, then used rundll32 and a Startup-folder shortcut for persistence. The first stage performed system reconnaissance and HTTP POST beacons to command-and-control scripts hosted on compromised legitimate sites, with collected victim data compressed, encrypted, and logged by the backend. The report frames Lazarus/APT38/Hidden Cobra attribution as likely and focuses on the early kill chain, victim filtering, and second-stage delivery controls.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | curiofirenze.com | 2019-11-05 | 2021-02-25 |
| HASH | 26a2fa7b45a455c311fd57875d8231c… | 2019-11-05 | 2020-05-15 |
| HASH | ec254c40abff00b104a949f07b7b642… | 2019-11-05 | 2020-05-15 |
| HASH | 1a172d92638e6fdb2858dcca7a78d4b… | 2019-11-05 | 2019-11-12 |
| IPv4 | 193.70.64.163 | 2019-11-05 | 2019-11-12 |
| HASH | adf86d77eb4064c52a3e4fb3f1c3218… | 2019-11-05 | 2019-11-05 |
| HASH | b018639e9a5f3b2b9c257b83ee51a3f… | 2019-11-05 | 2019-11-05 |