Hidden Cobra - from a shed skin to the viper’s nest

2020-06-23 Reversing Labs

https://blog.reversinglabs.com/blog/hidden-cobra

Thumbnail for Hidden Cobra - from a shed skin to the viper’s nest

ReversingLabs describes Hidden Cobra, often referred to as Lazarus, as a North Korea-linked APT and uses U.S. government reporting on COPPERHEDGE, TAINTEDSCRIBE, and PEBBLEDASH to show how defenders can expand IOC coverage. The article focuses on similarity hunting in Titanium Platform, starting from published samples and metadata such as import loading behavior, command indexes, and plaintext C2 domains. Its CTI value is finding related malware samples beyond released IOC lists, rather than reporting a new intrusion.

Indicators of Compromise

Type Value First Seen Last Seen
YARA Copperhedge_F 2020-06-23 2020-06-23
HASH 9ff4836ff1670816995297234cb5f6e… 2020-06-23 2020-06-23
HASH 588a298b51921f4ee8f6fb7ec837f80… 2020-06-23 2020-06-23
HASH 49379896fa096f523e55f8daf1db00c… 2020-06-23 2020-06-23
HASH 17e5e9fcd31ba8df50ef5474c271216… 2020-06-23 2020-06-23
HASH 3a25b9bd8c0995c5a2e2a3a31fe4691… 2020-06-23 2020-06-23
HASH 14b681e0c9ce9a02f2fb093927f043b… 2020-06-23 2020-06-23
HASH b5e134bc58f8eda4efd99a45628eb43… 2020-06-23 2020-06-23
HASH 78925505b266e973ad7b5ec5b28c0f7… 2020-06-23 2020-06-23
HASH 5692a8fb1e5c1f0802c8e552dd04308… 2020-06-23 2020-06-23
HASH b233b56cd9a11a273df389b98431f1d… 2020-06-23 2020-06-23
HASH e211559f3dfc6db100958b8c12e20f0… 2020-06-23 2020-06-23
HASH 2c879a1d4b6334c59ac5f11c2038d27… 2020-06-23 2020-06-23
HASH 0faf5540bcb8782dd70bcb31f3aa9ba… 2020-06-23 2020-06-23
HASH f744f5f97ace1a4862e764971449c28… 2020-06-23 2020-06-23
HASH 03138278b603bc120b2cba001a8adb0… 2020-06-23 2020-06-23
HASH ef0c0ef95b1542184a6a1f4d1f4ece5… 2020-06-23 2020-06-23
HASH fe0f8a37887c8f8fb5eb3e8252a8df3… 2020-06-23 2020-06-23
HASH 8c6d92becc487dc0043e446f99f165b… 2020-06-23 2020-06-23
HASH 84f3437bbccb514d639c0a613429826… 2020-06-23 2020-06-23
HASH 976553cafd72f8e1908f81f297fbc7d… 2020-06-23 2020-06-23
HASH 7202fea74865e085104f839574cd150… 2020-06-23 2020-06-23
IPv4 221.161.45.202 2020-06-23 2020-06-23
IPv4 61.106.174.191 2020-06-23 2020-06-23
HASH 29ddf9baad018518060814a03d424f4… 2018-08-07 2020-06-23

Related Actors

Related Reports

« Back