대북 관련 특정인을 타겟으로 하는 악성 워드 문서

2022-08-19 Ahnlab Malicious word document targeting specific people related to North Korea

https://asec.ahnlab.com/ko/37879/

Thumbnail for 대북 관련 특정인을 타겟으로 하는 악성 워드 문서

AhnLab reports malicious Word documents targeting individuals connected to North Korea and security affairs, with filenames crafted around unification, Korean Peninsula security, and named experts. The documents contain VBA macros matching a Kimsuky Word-document pattern and use PowerShell to download scripts from vjdif.mypressonline[.]com. The scripts collect host and process information, write data to %APPDATA%\Ahnalb\Ahnlab.hwp, exfiltrate it to post.php, establish persistence through a Startup shortcut, weaken Office macro warning settings, and log keystrokes. Listed detections include Downloader/DOC.Kimsuky and Trojan/PowerShell.FileUpload, with IOCs including 6f9c20f8f7f28a732b0853929a06b79c and ng.txt, ng.down, and post.php URLs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6f9c20f8f7f28a732b0853929a06b79c 2022-08-19 2022-08-19
URL http://vjdif.mypressonline.com/… 2022-08-19 2022-08-19
URL http://vjdif.mypressonline.com/… 2022-08-19 2022-08-19
URL http://vjdif.mypressonline.com/… 2022-08-19 2022-08-19
DOMAIN vjdif.mypressonline.com 2022-08-19 2022-08-19

Related Actors

Related Reports

« Back