대북관련 본문 내용의 External 링크를 이용한 악성 워드 문서
2021-03-22 • Ahnlab • Malicious word document using external links in North Korea-related content •
AhnLab reports malicious Word documents using North Korea-related lure content and external XML links, likely distributed by email to recipients working on DPRK-related issues. The documents connected to external URLs to download additional malicious Word macro files; examples included documents titled as questionnaires, work reports and North Korean party congress assessments, with infrastructure such as inonix.co.kr, koreacit.co.kr, anpcb.co.kr and reform-ouen.com paths. Recovered macro documents used obfuscated VBA to create and execute XML from the user’s Microsoft Templates directory, then attempted additional malicious network connections that were likely intended to download and run further payloads. AhnLab detected the files as Downloader/DOC.External, Downloader/XML.Generic and related downloader families.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://reform-ouen.com/wp-incl… | 2021-03-22 | 2021-07-26 |
| URL | http://www.anpcb.co.kr/plugin/s… | 2021-03-22 | 2021-07-26 |
| URL | http://koreacit.co.kr/skin/new/… | 2021-03-22 | 2021-07-26 |
| URL | http://www.inonix.co.kr/kor/boa… | 2021-03-22 | 2021-07-26 |
| DOMAIN | reform-ouen.com | 2021-03-22 | 2021-07-26 |
| DOMAIN | koreacit.co.kr | 2021-03-22 | 2021-07-26 |