Skip to content

APT Lazarus group

Pradyumna Joshi edited this page Feb 23, 2021 · 4 revisions

Lazarus group - analysis links

PDF reports:

Analysis

Mitigation strategies

Analysis notes

Host artifacts

  • Amcache
  • Shimcache
  • SRUDB
  • Jumplist
  • userassist
  • sysmon/windows-evt logs
  • Prefetch
  • Volume shadow copy
  • registry analysis using regripper
  • Recycle bin
  • Analysis of Temporary internet files (DLL, EXE,powershell script files)- C:\Users<user name>\AppData\Local\Microsoft\Windows\Temporary Internet Files

Network artifacts

  • dns logs
  • firewall logs
  • router logs
  • UTM logs

Symantec AV log

  • anti-virus logs - C:\ProgramData\Symantec\Symantec Endpoint Protection%SEP Version%\Data\Quarantine\
  • SEP logs - C:\ProgramData\Symantec\Symantec Endpoint Protection%SEP Version%\Data\AV\Logs\

Note:

Clone this wiki locally