대북 관련 본문 내용 악성 워드의 지속 유포 정황 확인
2021-10-29 • Ahnlab • Confirming the continued distribution of malicious words related to North Korea •
AhnLab reports continued distribution of malicious Word documents containing North Korea-related lure content and macros similar to previously observed samples. Filenames referenced topics such as Chinese military strategy, broadcast questionnaires, policy networks, and cyber-safety correspondence, making the documents plausible for users interested in inter-Korean or policy issues. When macros were enabled, the documents removed protection or revealed hidden content and retrieved additional script or payload data from attacker-controlled URLs such as sarvice.medianewsonline[.]com and greengarden.kkk24[.]kr. The report lists related C2 paths and notes that this document family remains difficult for users to recognize because the decoy content appears relevant after macro execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | bipaf.org | 2021-10-29 | 2023-11-01 |
| HASH | 4d53584d4c322e536572766572584d4c | 2021-10-29 | 2021-10-29 |
| URL | http://smgfishing.co.kr/theme/b… | 2021-10-29 | 2021-10-29 |
| URL | http://bipaf.org/bbs/zipcode/st… | 2021-10-29 | 2021-10-29 |
| URL | http://sarvice.medianewsonline.… | 2021-10-29 | 2021-10-29 |
| URL | http://greengarden.kkk24.kr/mob… | 2021-10-29 | 2021-10-29 |
| URL | http://tinytalk.mygamesonline.o… | 2021-10-29 | 2021-10-29 |
| URL | http://sendlucky.scienceonthewe… | 2021-10-29 | 2021-10-29 |
| DOMAIN | tinytalk.mygamesonline.org | 2021-10-29 | 2021-10-29 |
| DOMAIN | sarvice.medianewsonline.com | 2021-10-29 | 2021-10-29 |
| DOMAIN | sendlucky.scienceontheweb.net | 2021-10-29 | 2021-10-29 |
| DOMAIN | greengarden.kkk24.kr | 2021-10-29 | 2021-10-29 |
| DOMAIN | smgfishing.co.kr | 2021-10-29 | 2021-10-29 |