뉴스 설문지로 위장하여 유포 중인 악성 워드 문서

2022-11-16 Ahnlab Malicious word document being distributed disguised as a news questionnaire

https://asec.ahnlab.com/ko/42163/

Thumbnail for 뉴스 설문지로 위장하여 유포 중인 악성 워드 문서

AhnLab analyzes a malicious Word document disguised as a CNA news questionnaire and related to earlier North Korea-themed Word lures. The password-protected document contains obfuscated VBA macros that create and execute VBScript, BAT, LNK, and PowerShell components under AppData. The downloaded scripts collect system and directory information, exfiltrate it to attacker infrastructure, and add FTP-based theft of Chrome and Edge user-data files. The infection chain also retains prior functions such as LNK creation, Office security setting changes, and keylogging.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 59be2b9a3e33057b3d80574764ab0952 2022-11-16 2022-11-25
HASH 8785b8e882eef125dc527736bb1c5704 2022-11-16 2022-11-25
HASH 89d972f89b336ee07733c72f6f89edc5 2022-11-16 2022-11-25
URL http://okihs.mypressonline.com/… 2022-11-16 2022-11-25
URL http://okihs.mypressonline.com/… 2022-11-16 2022-11-25
URL http://okihs.mypressonline.com/… 2022-11-16 2022-11-25
DOMAIN jojoa.mypressonline.com 2022-11-16 2022-11-25
DOMAIN okihs.mypressonline.com 2022-11-16 2022-11-25

Related Actors

Related Reports

« Back