{"id":18291372,"url":"https://github.com/jpcertcc/lazarus-research","last_synced_at":"2025-04-05T10:31:05.184Z","repository":{"id":97103478,"uuid":"431313579","full_name":"JPCERTCC/Lazarus-research","owner":"JPCERTCC","description":"Lazarus analysis tools and research report ","archived":false,"fork":false,"pushed_at":"2023-12-22T05:40:27.000Z","size":6592,"stargazers_count":55,"open_issues_count":0,"forks_count":11,"subscribers_count":11,"default_branch":"main","last_synced_at":"2025-03-21T03:03:32.387Z","etag":null,"topics":["malware","security"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/JPCERTCC.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"License","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2021-11-24T01:51:07.000Z","updated_at":"2024-10-13T18:05:44.000Z","dependencies_parsed_at":"2023-12-22T06:36:03.968Z","dependency_job_id":"856f9c5e-b722-4dae-b7b6-48eefb401e88","html_url":"https://github.com/JPCERTCC/Lazarus-research","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JPCERTCC%2FLazarus-research","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JPCERTCC%2FLazarus-research/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JPCERTCC%2FLazarus-research/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JPCERTCC%2FLazarus-research/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/JPCERTCC","download_url":"https://codeload.github.com/JPCERTCC/Lazarus-research/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247324545,"owners_count":20920672,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["malware","security"],"created_at":"2024-11-05T14:14:02.057Z","updated_at":"2025-04-05T10:31:01.482Z","avatar_url":"https://github.com/JPCERTCC.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Lazarus Research\n\nThis repository publishes analysis reports and analysis tools for Operation Dream Job and Operation JTrack for Lazarus.\n\n## Tools\n\nPython tools for analyzing malware.\n\n### blindingcan_rc4_post_decode.py\n\nPython script to decode URL parameter for BLINDINGCAN_RC4.\n\n![blindingcan_rc4_post_decode](images/blindingcan_rc4_post_decode.png)\n\n### blindingcan_aes_post_decode.py\n\nPython to decode POST data for BLINDINGCAN_AES.\n\n![blindingcan_aes_post_decode](images/blindingcan_aes_post_decode.png)\n\n## Research results\n\n### Slides\n\n* Hitcon 2021\n  - https://github.com/JPCERTCC/Lazarus-research/blob/main/slides/HITCON2021_Anatomy-of-COBRA.pdf\n\n* CODE BLUE 2021\n  - https://github.com/JPCERTCC/Lazarus-research/blob/main/slides/CODEBLUE2021_The-Lazarus-Groups-Attack-Operations-Targeting-Japan.pdf\n\n### TTPs\n\n* MITRE ATT\u0026CK® Mapping for Lazarus Group\n  - https://github.com/JPCERTCC/Lazarus-research/blob/main/TTP/MITRE_ATT%26CK_Mapping.md\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjpcertcc%2Flazarus-research","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjpcertcc%2Flazarus-research","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjpcertcc%2Flazarus-research/lists"}