방송국 사례비 지급을 사칭한 피싱 메일 주의
2023-12-29 • Hauri • Beware of phishing emails pretending to pay broadcasting station rewards •
https://hauri.co.kr/security/issue_view.html?intSeq=426&page=1&article_num=335
A Hauri analysis describes a phishing email campaign that used a broadcast-station honorarium lure to deliver a Windows shortcut file. The LNK chain authenticated to Dropbox, pulled encrypted PowerShell and PE payloads from attacker-controlled paths, decrypted them with AES and GZip stages, and established scheduled tasks under AppData for persistence. Later stages collected the victim IP address, created Dropbox log folders, monitored keystrokes and clipboard data, and wrote keylogging output to version.xml before sending it to a C2 endpoint under gbi????.com. The report provides representative file paths and hashes for version103.vbs, w{random}.ps1, and the final payload.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://api.dropboxapi.com/oaut… | 2023-12-29 | 2025-09-03 |
| HASH | dce864eabfbd6445682a4671a2fee1a9 | 2023-12-29 | 2024-04-17 |
| DOMAIN | dddon.kr | 2023-12-29 | 2024-04-17 |
| HASH | 66498ffe232da5691e0fb23d2b00c933 | 2023-12-29 | 2023-12-29 |
| HASH | 7649972a60a64258c3d484cca7d6464d | 2023-12-29 | 2023-12-29 |
| URL | http://dddon.kr/doc/nase/docx/1… | 2023-12-29 | 2023-12-29 |