MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 422384d25aa351a4eb6871ea50c3c96e83ec6f8ffdb3129adc5a4cf1b198c5c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Lazarus


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: 422384d25aa351a4eb6871ea50c3c96e83ec6f8ffdb3129adc5a4cf1b198c5c9
SHA3-384 hash: ac4d11f1f52bd618dcf4f02e300c9d2a5fd660ade05fa2bfa5e28f3def6a196cb69a976763274d0a85dc88619466f0b8
SHA1 hash: 9081b9cfb4f4b5a9e277b1d7924b471637007cd7
MD5 hash: 2eaa53ccb43cd38a1f0a28abcd7f6a30
humanhash: eight-connecticut-floor-california
File name:Password_link
Download: download sample
Signature Lazarus
File size:1'851 bytes
First seen:2022-08-05 13:12:41 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/octet-stream
ssdeep 24:8SYmJzl6TTDwr+/s8o0B2ARjVuWAbMlJwEacT+/2FXmT4I0:8+lWffoJUjjA4JwEPoMI
TLSH T1EA31AF04BAD55F10D2B28E76587AE61554F5BD41AE37C79D0780E2D92074100F53AF27
Reporter JAMESWT_WT
Tags:apt DangerousPassword Lazarus lnk

Intelligence


File Origin
# of uploads :
1
# of downloads :
418
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Payload URLs
URL
File name
https://www.googlesheet.info/NZrTnPVmtfjcSMz8n1hZZzvHQvUUEfFnIMAYliQuR+A=
LNK File
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
cmd cmd.exe evasive masquerade
Result
Threat name:
Unknown
Detection:
malicious
Classification:
rans
Score:
92 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Drops PE files to the user root directory
Found URL in windows shortcut file (LNK)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Windows shortcut file (LNK) contains suspicious command line arguments
Windows shortcut file (LNK) starts blacklisted processes
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 679312 Sample: Password_link Startdate: 05/08/2022 Architecture: WINDOWS Score: 92 65 www.googlesheet.info 2->65 73 Snort IDS alert for network traffic 2->73 75 Antivirus detection for URL or domain 2->75 77 Antivirus / Scanner detection for submitted sample 2->77 79 4 other signatures 2->79 9 cmd.exe 2 2->9         started        13 cmd.exe 1 2->13         started        signatures3 process4 file5 53 C:\Users\Public\mshta.exe (copy), PE32+ 9->53 dropped 55 C:\Users\Public\msh, PE32+ 9->55 dropped 81 Drops PE files to the user root directory 9->81 15 mshta.exe 25 9->15         started        20 conhost.exe 1 9->20         started        22 mshta.exe 24 13->22         started        24 conhost.exe 1 13->24         started        signatures6 process7 dnsIp8 67 www.googlesheet.info 155.138.219.140, 443, 49740, 49745 AS-CHOOPAUS United States 15->67 49 C:\Users\Public\scmp.exe, PE32+ 15->49 dropped 69 Windows shortcut file (LNK) starts blacklisted processes 15->69 71 Drops PE files to the user root directory 15->71 26 cmd.exe 1 15->26         started        28 cmd.exe 2 15->28         started        51 C:\Users\Public\ldmc.exe, PE32+ 22->51 dropped 30 cmd.exe 1 22->30         started        file9 signatures10 process11 process12 32 scmp.exe 1 26->32         started        35 scmp.exe 1 26->35         started        37 conhost.exe 26->37         started        39 notepad.exe 28->39         started        41 conhost.exe 28->41         started        43 ldmc.exe 1 30->43         started        45 ldmc.exe 1 30->45         started        47 conhost.exe 30->47         started        dnsIp13 57 www.googlesheet.info 32->57 59 www.googlesheet.info 35->59 61 www.googlesheet.info 43->61 63 www.googlesheet.info 45->63
Threat name:
Shortcut.Trojan.WinLnk
Status:
Malicious
First seen:
2022-08-05 13:13:06 UTC
File Type:
Binary
AV detection:
15 of 26 (57.69%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Modifies system certificate store
Opens file in notepad (likely ransom note)
Script User-Agent
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Loads dropped DLL
Blocklisted process makes network request
Executes dropped EXE
Malware Config
Dropper Extraction:
https://www.googlesheet.info/NZrTnPVmtfjcSMz8n1hZZzvHQvUUEfFnIMAYliQuR+A=
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:EXE_in_LNK
Author:@bartblaze
Description:Identifies executable artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments