대북 관련 특정인을 타겟으로 하는 악성 워드 문서
2022-08-19 • Ahnlab • Malicious word document targeting specific people related to North Korea •
AhnLab reports malicious Word documents targeting individuals connected to North Korea and security affairs, with filenames crafted around unification, Korean Peninsula security, and named experts. The documents contain VBA macros matching a Kimsuky Word-document pattern and use PowerShell to download scripts from vjdif.mypressonline[.]com. The scripts collect host and process information, write data to %APPDATA%\Ahnalb\Ahnlab.hwp, exfiltrate it to post.php, establish persistence through a Startup shortcut, weaken Office macro warning settings, and log keystrokes. Listed detections include Downloader/DOC.Kimsuky and Trojan/PowerShell.FileUpload, with IOCs including 6f9c20f8f7f28a732b0853929a06b79c and ng.txt, ng.down, and post.php URLs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6f9c20f8f7f28a732b0853929a06b79c | 2022-08-19 | 2022-08-19 |
| URL | http://vjdif.mypressonline.com/… | 2022-08-19 | 2022-08-19 |
| URL | http://vjdif.mypressonline.com/… | 2022-08-19 | 2022-08-19 |
| URL | http://vjdif.mypressonline.com/… | 2022-08-19 | 2022-08-19 |
| DOMAIN | vjdif.mypressonline.com | 2022-08-19 | 2022-08-19 |