대북 관련 APT 악성코드

2016-11-18 Sands Lab APT malware related to North Korea

http://story.malwares.com/92

malwares.com analyzed malicious Hangul Word Processor documents that exploited a vulnerability rather than relying on macros, allowing code execution when the document was opened in affected HWP versions. The embedded BinData area contained shellcode obfuscated with XOR 0xD5, which attempted to download an additional payload with URLDownloadToFileA and execute it as wins.exe via WinExec. The primary sample used SHA-256 0D56C5F20B2DA3659F05D613D3FAEB41D9E82A45E9161C3B48805EBB7B2730B9 and tried to fetch http://crystalpowercleaning.com/wp-includes/images/wpindex.jpg, while similar samples referenced acddesigns.com.au and portmultimedia.com download paths. The additional payloads were no longer available during analysis, but the author warned that reuse of the same HWP vulnerability could have significant impact because the lure was a document file rather than an executable. The hosting sites appeared to be legitimate web services, and weak administrative access may have allowed attackers to upload the staged payloads.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN acddesigns.com.au 2016-11-18 2019-05-14
HASH 0d56c5f20b2da3659f05d613d3faeb4… 2016-11-18 2016-11-18
HASH 7875614ecd08474662a7aa2a1d8830b… 2016-11-18 2016-11-18
HASH cfe2c79a879d40ba95b4b69d955536b… 2016-11-18 2016-11-18
URL http://crystalpowercleaning.com… 2016-11-18 2016-11-18
URL http://acddesigns.com.au/client… 2016-11-18 2016-11-18
URL http://www.portmultimedia.com/w… 2016-11-18 2016-11-18
DOMAIN crystalpowercleaning.com 2016-11-18 2016-11-18

Related Reports

« Back