라자루스 그룹이 사용한 안티 포렌식 기법

2023-02-15 Ahnlab Anti-forensic techniques used by the Lazarus Group

https://asec.ahnlab.com/ko/47820/

Thumbnail for 라자루스 그룹이 사용한 안티 포렌식 기법

AhnLab analyzed anti-forensic techniques observed on systems compromised by the Lazarus Group in South Korea, including defense, satellite, software, and media-related environments. The report describes Lazarus hiding encrypted loader, PE, and configuration components under system-like folders and filenames, then decrypting them in memory to contact C2 and retrieve additional payloads. Investigators also observed artifact wiping, including overwritten-and-renamed malware deletion and bulk Prefetch cleanup, to frustrate recovery and execution tracing. A remaining backdoor was timestomped to match legitimate Windows files such as notepad.exe, showing selective timeline obfuscation used to conceal long-term access.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b457e8e9d92a1b31a4e2197037711783 2022-10-24 2023-10-13
HASH 8543667917a318001d0e331aeae3fb9b 2022-10-24 2023-10-13
HASH c16a6178a4910c6f3263a01929f306b9 2022-10-24 2023-10-13
HASH 1f1a3fe0a31bd0b17bc63967de0ccc29 2022-10-24 2023-10-13
HASH 202a7eec39951e1c0b1c9d0a2e24a4c4 2022-10-24 2023-10-13
HASH e73eab80b75887d4e8dd6df33718e3a5 2023-02-15 2023-06-14
HASH 747177aad5aef020b82c6aeabe5b174f 2023-02-15 2023-06-14
HASH 064d696a93a3790bd3a1b8b76baaeef3 2023-02-15 2023-06-14
HASH c09b062841e2c4d46c2e5270182d4272 2023-02-15 2023-06-14
HASH 67d306c163b38a06e98da5711e14c5a7 2023-02-15 2023-06-14
HASH ba741fa4c7b4bb97165644c799e29c99 2023-02-15 2023-06-14
HASH 61b3c9878b84706db5f871b4808e739a 2023-02-15 2023-02-27
HASH bd47942e9b6ad87eb5525040db620756 2023-02-15 2023-02-27
HASH c7256a0fbab0f437c3ad4334aa5cde06 2023-02-15 2023-02-27
HASH 27db56964e7583e19643bf5c98fffd52 2023-02-15 2023-02-27
HASH 6ea4e4ab925a09e4c7a1e80bae5b9584 2023-02-15 2023-02-27
HASH fc8b6c05963fd5285bce6ed51862f125 2023-02-15 2023-02-27
HASH ca9b6b3bce52d7f14babdba82345f5b1 2022-10-24 2023-02-15
HASH 97bc894205d696023395cbd844fa4e37 2022-10-24 2023-02-15
HASH 1e7d604fadd7d481dfadb66b9313865d 2022-04-18 2023-02-15
HASH 7870decbc7578da1656d1d1ff992313c 2022-04-18 2023-02-15
HASH b3e03a41ced8c8baa56b8b78f1d55c22 2022-04-18 2023-02-15

Related Actors

Related Reports

« Back