대북 관련 APT 악성코드
2016-11-18 • Sands Lab • APT malware related to North Korea •
malwares.com analyzed malicious Hangul Word Processor documents that exploited a vulnerability rather than relying on macros, allowing code execution when the document was opened in affected HWP versions. The embedded BinData area contained shellcode obfuscated with XOR 0xD5, which attempted to download an additional payload with URLDownloadToFileA and execute it as wins.exe via WinExec. The primary sample used SHA-256 0D56C5F20B2DA3659F05D613D3FAEB41D9E82A45E9161C3B48805EBB7B2730B9 and tried to fetch http://crystalpowercleaning.com/wp-includes/images/wpindex.jpg, while similar samples referenced acddesigns.com.au and portmultimedia.com download paths. The additional payloads were no longer available during analysis, but the author warned that reuse of the same HWP vulnerability could have significant impact because the lure was a document file rather than an executable. The hosting sites appeared to be legitimate web services, and weak administrative access may have allowed attackers to upload the staged payloads.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | acddesigns.com.au | 2016-11-18 | 2019-05-14 |
| HASH | 0d56c5f20b2da3659f05d613d3faeb4… | 2016-11-18 | 2016-11-18 |
| HASH | 7875614ecd08474662a7aa2a1d8830b… | 2016-11-18 | 2016-11-18 |
| HASH | cfe2c79a879d40ba95b4b69d955536b… | 2016-11-18 | 2016-11-18 |
| URL | http://crystalpowercleaning.com… | 2016-11-18 | 2016-11-18 |
| URL | http://acddesigns.com.au/client… | 2016-11-18 | 2016-11-18 |
| URL | http://www.portmultimedia.com/w… | 2016-11-18 | 2016-11-18 |
| DOMAIN | crystalpowercleaning.com | 2016-11-18 | 2016-11-18 |