국내 유명 포털사이트 위장한 정보유출 악성코드

2022-01-07 Ahnlab Information leakage malware disguised as a famous domestic portal site

https://asec.ahnlab.com/ko/30582/

Thumbnail for 국내 유명 포털사이트 위장한 정보유출 악성코드

ASEC analyzed an information-stealing Windows malware campaign delivered through Korean phishing infrastructure and disguised as a NAVER-related archive. The phishing flow redirects users from a Kakao-themed credential theft page to NAVER.zip, which contains an executable named as a Naver security tool. When run, the malware creates an Outlooka directory under AppData, drops AWasctUI.exe to collect host information and rdpclipe.exe to log keystrokes, and persists both through Startup folder shortcuts. It stores keylogging, systeminfo, and drive-tree output locally, exfiltrates files containing "UP" to 66.94.98[.]48/ESOK/post2.php, and can fetch additional data from the same server while showing an OTPGenerator decoy window.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://downfile.navers.com-pass… 2022-01-07 2022-01-07
URL http://mail2.daum.confirm-pw.li… 2022-01-07 2022-01-07
DOMAIN downfile.navers.com-pass.online 2022-01-07 2022-01-07
DOMAIN mail2.daum.confirm-pw.link 2022-01-07 2022-01-07
IPv4 66.94.98.48 2022-01-07 2022-01-07

Related Reports

« Back