링크 개체를 이용한 악성 한글문서(HWP) 주의 - 코인업체 사칭

2020-07-14 Ahnlab Warning on malicious HWP document using a linked object and impersonating a coin company

https://asec.ahnlab.com/1354

Thumbnail for 링크 개체를 이용한 악성 한글문서(HWP) 주의 - 코인업체 사칭

AhnLab analyzed a malicious HWP document impersonating a cryptocurrency company policy update and using a linked object/OLE executable named hanwordupdate.exe to trick users into launching it. The embedded EXE contains a Base64-encoded PowerShell script that copies itself from %TEMP% to %APPDATA%\svchost.exe and registers a HyperServer Run key for persistence. It builds a victim identifier from the system BIOS serial number and contacts http://kjdnc.gp114.net/data/log/do.php for command-and-control. If the attacker responds, the malware can execute commands, upload files to the C2, and download additional payloads, consistent with an APT-style document intrusion.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN kjdnc.gp114.net 2020-07-14 2021-12-04
URL http://kjdnc.gp114.net/data/log… 2020-07-14 2021-11-29

Related Reports

« Back