뉴스 설문지로 위장하여 유포 중인 악성 워드 문서
2022-11-16 • Ahnlab • Malicious word document being distributed disguised as a news questionnaire •
AhnLab analyzes a malicious Word document disguised as a CNA news questionnaire and related to earlier North Korea-themed Word lures. The password-protected document contains obfuscated VBA macros that create and execute VBScript, BAT, LNK, and PowerShell components under AppData. The downloaded scripts collect system and directory information, exfiltrate it to attacker infrastructure, and add FTP-based theft of Chrome and Edge user-data files. The infection chain also retains prior functions such as LNK creation, Office security setting changes, and keylogging.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 59be2b9a3e33057b3d80574764ab0952 | 2022-11-16 | 2022-11-25 |
| HASH | 8785b8e882eef125dc527736bb1c5704 | 2022-11-16 | 2022-11-25 |
| HASH | 89d972f89b336ee07733c72f6f89edc5 | 2022-11-16 | 2022-11-25 |
| URL | http://okihs.mypressonline.com/… | 2022-11-16 | 2022-11-25 |
| URL | http://okihs.mypressonline.com/… | 2022-11-16 | 2022-11-25 |
| URL | http://okihs.mypressonline.com/… | 2022-11-16 | 2022-11-25 |
| DOMAIN | jojoa.mypressonline.com | 2022-11-16 | 2022-11-25 |
| DOMAIN | okihs.mypressonline.com | 2022-11-16 | 2022-11-25 |