국내 학술대회 시즌을 노린 한글문서(HWP) 악성코드 유포 중

2020-06-04 Ahnlab Hangul document (HWP) malware is being distributed targeting the domestic academic conference season.

https://asec.ahnlab.com/1329

Thumbnail for 국내 학술대회 시즌을 노린 한글문서(HWP) 악성코드 유포 중

AhnLab ASEC reported malicious HWP documents tailored to South Korea’s domestic academic conference season, likely exploiting the summer paper-submission period and reusing behavior seen in earlier HWP/EPS malware. The documents displayed little or no normal content and used embedded EPS shellcode to download a BAT script and Base64-encoded CAB archive from resulview.com infrastructure. The CAB contents registered persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, collected host information, uploaded it to hxxp://resulview.com/5hadr/upload.php, and supported additional downloads for follow-on activity. The source does not name an actor, but it provides detection value around HWP/EPS exploitation, repeated shellcode/XOR patterns, and the listed resulview.com C2 paths.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://resulview.com/5hado/no1.… 2020-06-04 2020-06-04
URL http://resulview.com/5hado/vbs.… 2020-06-04 2020-06-04
URL http://resulview.com/5hado/%COM… 2020-06-04 2020-06-04
URL http://resulview.com/5hadr/uplo… 2020-06-04 2020-06-04
DOMAIN resulview.com 2020-06-04 2020-06-04

Related Reports

« Back