Volgmer - Comprehensive Threat Intelligence Report
2017-11-14 • Bloo •
Volgmer is a Windows backdoor attributed in the source to North Korea's Lazarus Group, also known as Hidden Cobra, and described as active from at least 2013-2014 through later campaigns. It installs as a legitimate-looking service with a random name, stores encrypted configuration in the registry, tampers with timestamps, and gives operators remote control for system discovery, file transfer, process execution, and command execution. The source says Volgmer used custom C2 communications over ports such as 8080 and 8088, sometimes with SSL or web-like requests using a misspelled "Mozillar" user agent. Reported targeting spans South Korea and later global government, military, financial, critical infrastructure, defense, high-tech, and related sectors, making it relevant to long-running Lazarus espionage and foothold operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7f953c6988d829c9c4ac2002572c9055 | 2017-11-14 | 2023-10-13 |
| HASH | ea5d322648ff108b1c9cbdd1ef4a5959 | 2017-11-14 | 2023-10-13 |
| HASH | b1225fa644eebafba07f0f5e404bd4fd | 2017-11-14 | 2023-10-13 |
| HASH | 64965a88e819fb93dbabafc4e3ad7b6c | 2017-11-14 | 2023-10-13 |
| HASH | 3e6119ebfacd1d88acbd2ca460c70b49 | 2017-11-14 | 2023-10-13 |
| HASH | c2ab2a8ffdc18c24080e889a634ef279 | 2017-11-14 | 2023-10-13 |
| HASH | 72756e6ebb8274d9352d8d1e7e505906 | 2017-11-14 | 2023-10-13 |
| HASH | 570a4253ae80ee8c2b6b23386e273f3a | 2017-11-14 | 2023-10-13 |
| HASH | 5473fa2c5823fbab2b94e8d5c44bc7b4 | 2017-11-14 | 2023-10-13 |
| HASH | cf2ff5b59c638a06d8b81159b9a435ea | 2017-11-14 | 2023-10-13 |
| HASH | 44fa8daa347ef5dd107bf123b4688797 | 2017-11-14 | 2023-10-13 |
| HASH | 5c87373eef090bed525b80aef398ee8a | 2017-11-14 | 2023-10-13 |
| HASH | a545f548b09fdf61405f5cc07e4a7fa1 | 2017-11-14 | 2023-10-13 |
| HASH | 226cc1f17c4625837b37b5976acbd68e | 2017-11-14 | 2023-10-13 |
| HASH | 1e2acecce7b5e9045b07d65e9e8afe1f | 2017-11-14 | 2023-10-13 |
| HASH | 9a87f19609f28d7f7d76f9759864bd08 | 2017-11-14 | 2023-10-13 |
| HASH | 1ecd83ee7e4cfc8fed7ceb998e75b996 | 2017-11-14 | 2023-10-13 |
| HASH | fe32303e69b201f9934248cc06b32ef8 | 2017-11-14 | 2023-10-13 |
| HASH | 17eacf4b4ae2ca4b07672dcc12e4d66d | 2017-11-14 | 2023-10-13 |
| HASH | 0171c4a0a53188fe6f9c3dfcc5722be6 | 2017-11-14 | 2023-10-13 |
| HASH | 6da7d8aec65436e1350f1c0dfc4016b7 | 2017-11-14 | 2023-10-13 |
| HASH | 35f9cfe5110471a82e330d904c97466a | 2017-11-14 | 2023-10-13 |
| HASH | 85b6e4ea8707149b48e41454cbd0d5ad | 2017-11-14 | 2023-10-13 |
| HASH | eb9db98914207815d763e2e5cfbe96b9 | 2017-11-14 | 2023-10-13 |
| HASH | 693afaedf740492df2a09dfcc08a3dff | 2017-11-14 | 2023-10-13 |
| HASH | e3d03829cbec1a8cca56c6ae730ba9a8 | 2017-11-14 | 2023-10-13 |
| HASH | e273803ae6724a714b970dd86ca1acd0 | 2017-11-14 | 2023-10-13 |
| HASH | d52b5d8c20964333f79ff1bce3385d0b | 2017-11-14 | 2023-10-13 |
| HASH | 6e21cc6669ada41e48b369b64ec5f37b | 2017-11-14 | 2023-10-13 |
| HASH | 8b3ec4b9c7ad20af418e89ca6066a3ad | 2017-11-14 | 2023-10-13 |
| HASH | 4753679cef5162000233d69330208420 | 2017-11-14 | 2023-10-13 |
| HASH | 5dd1ccc8fb2a5615bf5656721339efed | 2017-11-14 | 2023-10-13 |
| HASH | 947124467bd04b7624d9b31e02b5ee7f | 2017-11-14 | 2023-10-13 |
| HASH | 9a5fa5c5f3915b2297a1c379be9979f0 | 2017-05-22 | 2023-10-13 |
| HASH | eff3e37d0406c818e3430068d90e7ed… | 2017-11-14 | 2020-03-09 |
| HASH | e40a46e95ef792cf20d5c14a9ad0b3a… | 2017-11-14 | 2020-03-09 |
| HASH | ff2eb800ff16745fc13c216ff6d5cc2… | 2017-11-14 | 2020-03-09 |
| HASH | fee0081df5ca6a21953f3a633f2f64b… | 2017-11-14 | 2020-03-09 |
| HASH | 1d0999ba3217cbdb0cc85403ef75587… | 2017-11-14 | 2020-03-09 |
| HASH | 6dae368eecbcc10266bba32776c40d9… | 2017-11-14 | 2020-03-09 |
| HASH | 9f177a6fb4ea5af876ef8a0bf954e37… | 2017-05-22 | 2020-03-09 |
| IPv4 | 120.234.15.199 | 2017-11-14 | 2017-11-14 |
| IPv4 | 148.97.97.195 | 2017-11-14 | 2017-11-14 |
| IPv4 | 157.204.231.83 | 2017-11-14 | 2017-11-14 |
| IPv4 | 20.9.116.186 | 2017-11-14 | 2017-11-14 |
| IPv4 | 97.71.67.186 | 2017-11-14 | 2017-11-14 |
| IPv4 | 194.244.28.113 | 2017-11-14 | 2017-11-14 |
| IPv4 | 42.188.190.89 | 2017-11-14 | 2017-11-14 |
| IPv4 | 130.176.242.24 | 2017-11-14 | 2017-11-14 |
| IPv4 | 70.190.93.78 | 2017-11-14 | 2017-11-14 |
| IPv4 | 99.222.131.203 | 2017-11-14 | 2017-11-14 |
| IPv4 | 35.223.16.103 | 2017-11-14 | 2017-11-14 |
| IPv4 | 133.69.42.200 | 2017-11-14 | 2017-11-14 |
| IPv4 | 218.224.232.84 | 2017-11-14 | 2017-11-14 |
| IPv4 | 179.145.48.116 | 2017-11-14 | 2017-11-14 |
| IPv4 | 172.198.149.186 | 2017-11-14 | 2017-11-14 |
| IPv4 | 181.87.187.210 | 2017-11-14 | 2017-11-14 |