국내 유명 포털사이트 위장한 정보유출 악성코드
2022-01-07 • Ahnlab • Information leakage malware disguised as a famous domestic portal site •
ASEC analyzed an information-stealing Windows malware campaign delivered through Korean phishing infrastructure and disguised as a NAVER-related archive. The phishing flow redirects users from a Kakao-themed credential theft page to NAVER.zip, which contains an executable named as a Naver security tool. When run, the malware creates an Outlooka directory under AppData, drops AWasctUI.exe to collect host information and rdpclipe.exe to log keystrokes, and persists both through Startup folder shortcuts. It stores keylogging, systeminfo, and drive-tree output locally, exfiltrates files containing "UP" to 66.94.98[.]48/ESOK/post2.php, and can fetch additional data from the same server while showing an OTPGenerator decoy window.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://downfile.navers.com-pass… | 2022-01-07 | 2022-01-07 |
| URL | http://mail2.daum.confirm-pw.li… | 2022-01-07 | 2022-01-07 |
| DOMAIN | downfile.navers.com-pass.online | 2022-01-07 | 2022-01-07 |
| DOMAIN | mail2.daum.confirm-pw.link | 2022-01-07 | 2022-01-07 |
| IPv4 | 66.94.98.48 | 2022-01-07 | 2022-01-07 |