공격자 메일에 회신한 경우에 외부 링크로 제공되는 워드문서 (Kimsuky)
2022-07-26 • Ahnlab • Word documents delivered through external links after replying to attacker emails (Kimsuky) •
AhnLab reported continued Kimsuky distribution of malicious Word documents themed around North Korea-related work, including resume, interim-report, advisory-request, and webinar lures. In one flow, the attacker impersonated a domestic organization and only sent an external download link after the recipient replied positively to the initial email, leading through a credential-harvesting URL and likely document download path. The documents used Korean macro-enable decoy images and VBA macros that created a version.ini script or copied mshta.exe to gtfmon.exe, then attempted to contact asssambly.mywebcommunity[.]org or freunkown1.sportsontheweb[.]net. AhnLab warns that the activity reflects persistent Kimsuky use of socially engineered Word documents and external links against users handling DPRK-related topics.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | freunkown1.sportsontheweb.net | 2022-07-26 | 2022-07-29 |
| HASH | 7fe055d5aa72bd50470da61985e12a8a | 2022-07-26 | 2022-07-26 |
| HASH | 357ef37979b02b08120895ae5175eb0a | 2022-07-26 | 2022-07-26 |
| URL | http://freunkown1.sportsonthewe… | 2022-07-26 | 2022-07-26 |
| URL | http://asssambly.mywebcommunity… | 2022-07-26 | 2022-07-26 |
| URL | https://accounts.serviceprotect… | 2022-07-26 | 2022-07-26 |
| DOMAIN | asssambly.mywebcommunity.org | 2022-07-26 | 2022-07-26 |
| DOMAIN | accounts.serviceprotect.eu | 2022-07-26 | 2022-07-26 |