$ cat writeup.md…
$ cat writeup.md…
hackthebox
As a Threat Intelligence Analyst investigating **Operation Dream Job**, you have identified that the **Lazarus Group** utilized a variety of custom-built malware and tools to facilitate their operations. Your task is to analyze and gather intelligence on the malware utilized by this APT.
$ cat /etc/rate-limit
Rate limit reached (20 reads/hour per IP). Showing preview only — full content returns at the next hour roll-over.
As a Threat Intelligence Analyst investigating Operation Dream Job, you have identified that the Lazarus Group utilized a variety of custom-built malware and tools to facilitate their operations. Your task is to analyze and gather intelligence on the malware utilized by this APT.
Files provided:
17.dotm — Malicious Word template with VBA macroBAE_HPC_SE.iso — ISO file containing trojanized SumatraPDFSalary_Lockheed_Martin_job_opportunities_confidential.doc — Phishing document with VBA macroDvn62WlNrt09This is a 13-task Sherlock scenario combining MITRE ATT&CK threat intelligence research, malware artifact forensics, and OSINT to investigate the Lazarus Group's Operation Dream Job campaign. The challenge requires analyzing two custom malware families (DRATzarus, Torisma) via MITRE ATT&CK, performing forensic analysis on an ISO-delivered trojanized executable, and extracting intelligence from malicious VBA macros in Office documents.
Operation Dream Job is a Lazarus Group campaign targeting defense and aerospace employees with fake job offers. The attack chain:
Salary_Lockheed_Martin_job_opportunities_confidential.doc with embedded VBA macrosInternalViewer.exe), DLL sideloading via wsuser.db| Malware | MITRE ID | Key Trait |
|---|---|---|
| DRATzarus | S0694 | Similar to Bankshot; uses IsDebuggerPresent for anti-debug |
| Torisma | S0678 | C2 encrypted with XOR + VEST-32; packed with LZ4 compression |
Answer: Bankshot
...
$ grep --similar