링크 개체를 이용한 악성 한글문서(HWP) 주의 - 코인업체 사칭
2020-07-14 • Ahnlab • Warning on malicious HWP document using a linked object and impersonating a coin company •
AhnLab analyzed a malicious HWP document impersonating a cryptocurrency company policy update and using a linked object/OLE executable named hanwordupdate.exe to trick users into launching it. The embedded EXE contains a Base64-encoded PowerShell script that copies itself from %TEMP% to %APPDATA%\svchost.exe and registers a HyperServer Run key for persistence. It builds a victim identifier from the system BIOS serial number and contacts http://kjdnc.gp114.net/data/log/do.php for command-and-control. If the attacker responds, the malware can execute commands, upload files to the C2, and download additional payloads, consistent with an APT-style document intrusion.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | kjdnc.gp114.net | 2020-07-14 | 2021-12-04 |
| URL | http://kjdnc.gp114.net/data/log… | 2020-07-14 | 2021-11-29 |