국내 학술대회 시즌을 노린 한글문서(HWP) 악성코드 유포 중
2020-06-04 • Ahnlab • Hangul document (HWP) malware is being distributed targeting the domestic academic conference season. •
AhnLab ASEC reported malicious HWP documents tailored to South Korea’s domestic academic conference season, likely exploiting the summer paper-submission period and reusing behavior seen in earlier HWP/EPS malware. The documents displayed little or no normal content and used embedded EPS shellcode to download a BAT script and Base64-encoded CAB archive from resulview.com infrastructure. The CAB contents registered persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, collected host information, uploaded it to hxxp://resulview.com/5hadr/upload.php, and supported additional downloads for follow-on activity. The source does not name an actor, but it provides detection value around HWP/EPS exploitation, repeated shellcode/XOR patterns, and the listed resulview.com C2 paths.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://resulview.com/5hado/no1.… | 2020-06-04 | 2020-06-04 |
| URL | http://resulview.com/5hado/vbs.… | 2020-06-04 | 2020-06-04 |
| URL | http://resulview.com/5hado/%COM… | 2020-06-04 | 2020-06-04 |
| URL | http://resulview.com/5hadr/uplo… | 2020-06-04 | 2020-06-04 |
| DOMAIN | resulview.com | 2020-06-04 | 2020-06-04 |