드론(무인항공기) 현황 내용의 한글(*.HWP) 악성코드 유포 중
2020-06-02 • Ahnlab • Spreading Hangul (*.HWP) malware containing drone (unmanned aerial vehicle) status information •
ASEC observed a malicious Korean HWP document themed around drone and unmanned-aerial-vehicle status information. When opened, the document runs embedded malicious EPS content that abuses CVE-2017-8291 to decode and execute shellcode, checks for AhnLab V3-related processes, and establishes persistence through a scheduled task named OneDrive. The task runs mshta every three minutes to retrieve an HTA payload from www.boaz[.]kr/skin/member/log/pre[.]hta. The source also provides hashes and AhnLab detections for the HWP exploit and downloader chain, making the report useful for tracking HWP/EPS lure delivery and scheduled-task based follow-on execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d3cb1e300d24ed407e35f277f19017c3 | 2020-06-02 | 2020-06-02 |
| HASH | 0b558ee89a7bb32968ef78104f6b9a28 | 2020-06-02 | 2020-06-02 |
| URL | http://www.boaz.kr/skin/member/… | 2020-06-02 | 2020-06-02 |