s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.lazagne

📛 Threat Title

Malware family: LaZagne

Category: LaZagne First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.lazagne`. Printable name: LaZagne.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.lazagne VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lazagne

IOC database

Type
domain
Value
py.lazagne
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.lazagne

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lazagne

References (1)

Remediations (10)

  • web:attack.mitre.org

    LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems.

  • web:blackpointcyber.com

    Mimikatz, LaZagne , and CredentialsFileView all running under the name of legitimate security tool "Automim," Raspberry Robin malware deployed via USB drive for initial access, and Malicious JavaScript file via a scheduled task for execution, persistence, and command and control (C2) communication using PowerShell.

  • web:detection.fyi

    Detects the execution of the LaZagne . A utility used to retrieve multiple types of passwords stored on a local computer. LaZagne has been leveraged multiple …

  • web:filestore.fortinet.com

    Detects Local Security Authority Subsystem Service (LSASS.exe) process access by LaZagne for credential dumping. LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system, including browsers and applications, as a low privileged user.

  • web:github.com

    The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext, APIs, custom algorithms, databases, etc.).

  • web:malpedia.caad.fkie.fraunhofer.de

    The author described LaZagne as an open source project used to retrieve lots of passwords stored on a local computer. It has been developed for the purpose of finding these passwords for the most commonly-used software. It is written in Python and provided as compiled standalone binaries for Linux, Mac, and Windows.

  • web:www.huntress.com

    LaZagne is an advanced credential-stealing malware designed to extract saved passwords and credentials from compromised systems. Often categorized as Post-Exploitation software, LaZagne is primarily leveraged by adversaries to gain unauthorized access to critical accounts and sensitive data. It is an open-source tool, widely misused by threat actors to automate credential theft efforts.

  • web:www.microsoft.com

    HackTool:Win32/ LaZagne , a well-known open-source tool, is utilized by threat actors to recover various types of sensitive information, particularly passwords, from targeted systems. The tool is designed to exploit vulnerabilities and weaknesses present in operating systems and applications, enabling the extraction of stored credentials.

  • web:www.paloaltonetworks.com

    Introduction Credential dumping is a technique commonly used by adversaries to extract account credentials from a compromised system. Attackers leverage well-known tools like Mimikatz, LaZagne , and hashcat to obtain passwords and hashes, which can then be used for lateral movement, privilege escalation, or persistence. To counteract this threat, Cortex XSIAM's Response and Remediation Pack ...

  • web:www.threatdown.com

    The ThreatDown Managed Detection and Response (MDR) team recently identified the RansomHub ransomware gang using a previously unseen method of attack using two tools: TDSSKiller, employed to disable endpoint detection and response (EDR) systems, and LaZagne , used to harvest credentials. Although both TDSSKiller and LaZagne have been used by attackers for years, this is the first record of ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.