Paleontology: The Unknown Origins of Lazarus Malware - Intezer
Tags
country: | North Korea |
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | 7f4750c8-71d9-44e2-8f50-1d7d084819f9 |
Fingerprint | e702131bcfe38252 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Oct. 31, 2018, 2:02 p.m. |
Added to db | Jan. 30, 2023, 4:35 p.m. |
Last updated | Nov. 17, 2024, 5:58 p.m. |
Headline | Paleontology: The Unknown Origins of Lazarus Malware |
Title | Paleontology: The Unknown Origins of Lazarus Malware - Intezer |
Detected Hints/Tags/Attributes | 22/2/25 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 14 | analyze.intezer.com |
|
Details | Domain | 5 | pudn.com |
|
Details | Domain | 23 | www.intezer.com |
|
Details | Domain | 1 | ready-jetkorea.com |
|
Details | Domain | 1 | plsong.com |
|
Details | File | 1 | dlltroy.dll |
|
Details | File | 1 | casper.cpp |
|
Details | File | 1 | casper_trojan.cpp |
|
Details | File | 748 | kernel32.dll |
|
Details | File | 1 | casper_inject.cpp |
|
Details | File | 1 | write_ok.php |
|
Details | sha256 | 1 | 458ffcc41959599f8dab1fd4366c9a50efefa376e42971c4a436aa7fd697a396 |
|
Details | sha256 | 1 | d1cf03fbcb6471d44b914c2720821582fb3dd81cb543f325b2780a5e95046395 |
|
Details | sha256 | 1 | ec73fe2ecc2e0425e4aeb1f01581b50c5b1f8e85475c20ea409de798e6469608 |
|
Details | sha256 | 1 | c62ec66e45098d2c41bfd7a674a5f76248cf4954225c2d3a2cfcd023daa93522 |
|
Details | sha256 | 1 | 926a2e8c2baa90d504d48c0d50ca73e0f400d565ee6e07ad6dafdd0d7b948b0e |
|
Details | sha256 | 1 | f4b7b36e9c940937748d5bba3beb82b7c3636f084e5e913c7a5ad3ad623ffbc5 |
|
Details | sha256 | 1 | 1b6a1320fba00dd2e56e35cf6f11f941deabcb6e4dba7ea773ded7e3d648ec54 |
|
Details | sha256 | 1 | 068b89e2ec5655d006f2788ea328e5f12bd57ba761ee03c4de2fb0aa01c92c7f |
|
Details | sha256 | 1 | 4915f53221dc7786710a7a82a9cb00cf8468e0d1155a1355c9eb17e8cddfd265 |
|
Details | sha256 | 1 | 6724c041fe0df61a619006bf1df4a759f4f22a65e2afda32501760ebc9ebe25d |
|
Details | Url | 8 | https://analyze.intezer.com/# |
|
Details | Url | 1 | https://www.intezer.com//blockbusted-lazarus-blockbuster-north-korea |
|
Details | Url | 1 | http://ready-jetkorea.com/data/file/pop/write_ok.php |
|
Details | Url | 1 | http://plsong.com/xe/addons/counter/conf/write_ok.php |