Lazarus 위협 그룹의 Volgmer, Scout 악성코드 분석 보고서

2023-10-04 Ahnlab Volgmer, Scout malware analysis report from the Lazarus threat group

https://asec.ahnlab.com/ko/57427/

Thumbnail for Lazarus 위협 그룹의 Volgmer, Scout 악성코드 분석 보고서

AhnLab analyzes Lazarus malware families Volgmer and Scout, describing Volgmer as a backdoor used from 2014 through about 2021 and Scout as a downloader observed from around 2022. The report links Scout to attacks that exploited vulnerabilities in Korean financial security certification software and targeted domestic defense, manufacturing, ICT, financial, media, satellite, and software organizations. Volgmer droppers installed DLL backdoors as Windows services, stored encrypted configuration and C2 data under HKLM\SYSTEM\CurrentControlSet\Control\WMI\Security, randomized service names, and timestomped files to match notepad.exe. AhnLab notes shared encryption material and similar operating patterns across later Lazarus and Andariel-linked malware, including BYOVD use to disable security products.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a76624578ed42cceba81c76660977562 2023-10-04 2023-10-13
HASH 394b05394ebb9b239a063a6b5839edb9 2023-10-04 2023-10-13
HASH 4b1f1db4f169ca6b57015b313d665045 2023-10-04 2023-10-13
HASH c41eb1ea59fab31147c5b107cc1c5a51 2023-10-04 2023-10-13
HASH 05bb1d8b7e62f4305d97042f07c64679 2023-10-04 2023-10-13
HASH 76f02ab112b8e077544d0c0a6e0c428a 2023-10-04 2023-10-13
HASH 80d34f9ca10b0e8b49c02139e4615b7a 2023-10-04 2023-10-13
HASH 695e5b8dc9615ec603fe2cbb7326a50f 2023-10-04 2023-10-13
HASH fa3e49c877a95f37fd25dbd62f9e274c 2023-10-04 2023-10-13
HASH 7ba37d662f19bef27c3da2fd2cee0e3a 2023-10-04 2023-10-13
HASH 855e26d530e69ddc77bb19561fb19d90 2023-10-04 2023-10-13
HASH b517e7ad07d1182feb4b8f61549ff233 2023-10-04 2023-10-13
HASH bf5d815597018fe7f3dfb52d4f7e1f65 2023-10-04 2023-10-13
HASH 8f919e6d8970faede0b10cfd5f82da5… 2023-10-04 2023-10-13
HASH 7f0e773397808b4328ad11d6948a683f 2023-10-04 2023-10-13
HASH c07e04d388fb394ac190aace51c03c33 2023-10-04 2023-10-13
HASH 8766fe8380b144907efa286a814c2241 2023-10-04 2023-10-13
HASH 35943aa640e122fcb127b2bfd6e29816 2023-10-04 2023-10-13
HASH 0b78347acf76d4bb66212bf9a41b9fb9 2023-10-04 2023-10-13
HASH 5496adcd712d4378950ba62ad4c2423b 2023-10-04 2023-10-13
HASH 0b746394c9d23654577f4c0f2a39a543 2023-10-04 2023-10-13
HASH 0ed86587124f08325cd8f3d3d2556292 2023-10-04 2023-10-13
HASH cc5a8a15d5808002e62d5daf2d4f31b3 2023-10-04 2023-10-13
HASH 64cac69ab1e9108e0035f9ce38b47db7 2023-10-04 2023-10-13
HASH 9ec3a4257564658f651896abc608680e 2023-10-04 2023-10-13
HASH 1c89fb4aee20020bfd75713264df97cd 2023-10-04 2023-10-13
HASH 225cdc9b452b6d5a3f7616dcc9333d7d 2023-10-04 2023-10-13
HASH b457e8e9d92a1b31a4e2197037711783 2022-10-24 2023-10-13
HASH fa868a38ceeb46ee9cf8bd441a67ae27 2022-10-24 2023-10-13
HASH 8543667917a318001d0e331aeae3fb9b 2022-10-24 2023-10-13
HASH c16a6178a4910c6f3263a01929f306b9 2022-10-24 2023-10-13
HASH 1f1a3fe0a31bd0b17bc63967de0ccc29 2022-10-24 2023-10-13
HASH 43f218d3a4b2199468b00a0b43f51c79 2022-10-24 2023-10-13
HASH 202a7eec39951e1c0b1c9d0a2e24a4c4 2022-10-24 2023-10-13
HASH 7f953c6988d829c9c4ac2002572c9055 2017-11-14 2023-10-13
HASH ea5d322648ff108b1c9cbdd1ef4a5959 2017-11-14 2023-10-13
HASH b1225fa644eebafba07f0f5e404bd4fd 2017-11-14 2023-10-13
HASH 64965a88e819fb93dbabafc4e3ad7b6c 2017-11-14 2023-10-13
HASH 3e6119ebfacd1d88acbd2ca460c70b49 2017-11-14 2023-10-13
HASH c2ab2a8ffdc18c24080e889a634ef279 2017-11-14 2023-10-13
HASH 72756e6ebb8274d9352d8d1e7e505906 2017-11-14 2023-10-13
HASH 570a4253ae80ee8c2b6b23386e273f3a 2017-11-14 2023-10-13
HASH 5473fa2c5823fbab2b94e8d5c44bc7b4 2017-11-14 2023-10-13
HASH cf2ff5b59c638a06d8b81159b9a435ea 2017-11-14 2023-10-13
HASH 44fa8daa347ef5dd107bf123b4688797 2017-11-14 2023-10-13
HASH 5c87373eef090bed525b80aef398ee8a 2017-11-14 2023-10-13
HASH a545f548b09fdf61405f5cc07e4a7fa1 2017-11-14 2023-10-13
HASH 226cc1f17c4625837b37b5976acbd68e 2017-11-14 2023-10-13
HASH 1e2acecce7b5e9045b07d65e9e8afe1f 2017-11-14 2023-10-13
HASH 9a87f19609f28d7f7d76f9759864bd08 2017-11-14 2023-10-13
HASH 1ecd83ee7e4cfc8fed7ceb998e75b996 2017-11-14 2023-10-13
HASH fe32303e69b201f9934248cc06b32ef8 2017-11-14 2023-10-13
HASH 17eacf4b4ae2ca4b07672dcc12e4d66d 2017-11-14 2023-10-13
HASH 0171c4a0a53188fe6f9c3dfcc5722be6 2017-11-14 2023-10-13
HASH 6da7d8aec65436e1350f1c0dfc4016b7 2017-11-14 2023-10-13
HASH 35f9cfe5110471a82e330d904c97466a 2017-11-14 2023-10-13
HASH 85b6e4ea8707149b48e41454cbd0d5ad 2017-11-14 2023-10-13
HASH eb9db98914207815d763e2e5cfbe96b9 2017-11-14 2023-10-13
HASH 693afaedf740492df2a09dfcc08a3dff 2017-11-14 2023-10-13
HASH e3d03829cbec1a8cca56c6ae730ba9a8 2017-11-14 2023-10-13
HASH e273803ae6724a714b970dd86ca1acd0 2017-11-14 2023-10-13
HASH d52b5d8c20964333f79ff1bce3385d0b 2017-11-14 2023-10-13
HASH 6e21cc6669ada41e48b369b64ec5f37b 2017-11-14 2023-10-13
HASH 8b3ec4b9c7ad20af418e89ca6066a3ad 2017-11-14 2023-10-13
HASH 4753679cef5162000233d69330208420 2017-11-14 2023-10-13
HASH 5dd1ccc8fb2a5615bf5656721339efed 2017-11-14 2023-10-13
HASH 947124467bd04b7624d9b31e02b5ee7f 2017-11-14 2023-10-13
HASH 9a5fa5c5f3915b2297a1c379be9979f0 2017-05-22 2023-10-13

Related Reports

« Back