국내 인터넷 커뮤니티 사이트에서 악성코드 유포 (유틸리티 위장)

2020-07-23 Ahnlab Malware distributed on a Korean internet community site while disguised as a utility

https://asec.ahnlab.com/1360

Thumbnail for 국내 인터넷 커뮤니티 사이트에서 악성코드 유포 (유틸리티 위장)

AhnLab ASEC found malware distributed through a Korean community download board as a trojanized utility rather than a document lure. The attacker modified a legitimate utility executable by adding an executable .ireloc section with shellcode and changing execution flow so the normal program still ran while a malicious thread executed. The shellcode contacted C2 infrastructure, downloaded and decoded a payload, saved it as acview.dll in the temporary directory, and launched it with regsvr32. ASEC notes that the command pattern overlaps earlier Korean HWP vulnerability and Excel macro malware cases, and lists representative indicators including trebat[.]co and byliny[.]bionebe[.]cz URLs.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://byliny.bionebe.cz/wp-co… 2020-07-23 2020-07-23
DOMAIN byliny.bionebe.cz 2020-07-23 2020-07-23
« Back