드론(무인항공기) 현황 내용의 한글(*.HWP) 악성코드 유포 중

2020-06-02 Ahnlab Spreading Hangul (*.HWP) malware containing drone (unmanned aerial vehicle) status information

https://asec.ahnlab.com/1328

Thumbnail for 드론(무인항공기) 현황 내용의 한글(*.HWP) 악성코드 유포 중

ASEC observed a malicious Korean HWP document themed around drone and unmanned-aerial-vehicle status information. When opened, the document runs embedded malicious EPS content that abuses CVE-2017-8291 to decode and execute shellcode, checks for AhnLab V3-related processes, and establishes persistence through a scheduled task named OneDrive. The task runs mshta every three minutes to retrieve an HTA payload from www.boaz[.]kr/skin/member/log/pre[.]hta. The source also provides hashes and AhnLab detections for the HWP exploit and downloader chain, making the report useful for tracking HWP/EPS lure delivery and scheduled-task based follow-on execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d3cb1e300d24ed407e35f277f19017c3 2020-06-02 2020-06-02
HASH 0b558ee89a7bb32968ef78104f6b9a28 2020-06-02 2020-06-02
URL http://www.boaz.kr/skin/member/… 2020-06-02 2020-06-02

Related Reports

« Back