TF-MAL-py.lazagne
📛 Threat Title
Malware family: LaZagne
Description
ThreatFox malware family `py.lazagne`. Printable name: LaZagne.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.lazagne
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lazagne
IOC database
- Type
- domain
- Value
py.lazagne- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.lazagne
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lazagne
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems.
-
web:blackpointcyber.com
Mimikatz, LaZagne , and CredentialsFileView all running under the name of legitimate security tool "Automim," Raspberry Robin malware deployed via USB drive for initial access, and Malicious JavaScript file via a scheduled task for execution, persistence, and command and control (C2) communication using PowerShell.
-
web:detection.fyi
Detects the execution of the LaZagne . A utility used to retrieve multiple types of passwords stored on a local computer. LaZagne has been leveraged multiple …
-
web:filestore.fortinet.com
Detects Local Security Authority Subsystem Service (LSASS.exe) process access by LaZagne for credential dumping. LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system, including browsers and applications, as a low privileged user.
-
web:github.com
The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext, APIs, custom algorithms, databases, etc.).
-
web:malpedia.caad.fkie.fraunhofer.de
The author described LaZagne as an open source project used to retrieve lots of passwords stored on a local computer. It has been developed for the purpose of finding these passwords for the most commonly-used software. It is written in Python and provided as compiled standalone binaries for Linux, Mac, and Windows.
-
web:www.huntress.com
LaZagne is an advanced credential-stealing malware designed to extract saved passwords and credentials from compromised systems. Often categorized as Post-Exploitation software, LaZagne is primarily leveraged by adversaries to gain unauthorized access to critical accounts and sensitive data. It is an open-source tool, widely misused by threat actors to automate credential theft efforts.
-
web:www.microsoft.com
HackTool:Win32/ LaZagne , a well-known open-source tool, is utilized by threat actors to recover various types of sensitive information, particularly passwords, from targeted systems. The tool is designed to exploit vulnerabilities and weaknesses present in operating systems and applications, enabling the extraction of stored credentials.
-
web:www.paloaltonetworks.com
Introduction Credential dumping is a technique commonly used by adversaries to extract account credentials from a compromised system. Attackers leverage well-known tools like Mimikatz, LaZagne , and hashcat to obtain passwords and hashes, which can then be used for lateral movement, privilege escalation, or persistence. To counteract this threat, Cortex XSIAM's Response and Remediation Pack ...
-
web:www.threatdown.com
The ThreatDown Managed Detection and Response (MDR) team recently identified the RansomHub ransomware gang using a previously unseen method of attack using two tools: TDSSKiller, employed to disable endpoint detection and response (EDR) systems, and LaZagne , used to harvest credentials. Although both TDSSKiller and LaZagne have been used by attackers for years, this is the first record of ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.