방송국 사례비 지급을 사칭한 피싱 메일 주의

2023-12-29 Hauri Beware of phishing emails pretending to pay broadcasting station rewards

https://hauri.co.kr/security/issue_view.html?intSeq=426&page=1&article_num=335

Thumbnail for 방송국 사례비 지급을 사칭한 피싱 메일 주의

A Hauri analysis describes a phishing email campaign that used a broadcast-station honorarium lure to deliver a Windows shortcut file. The LNK chain authenticated to Dropbox, pulled encrypted PowerShell and PE payloads from attacker-controlled paths, decrypted them with AES and GZip stages, and established scheduled tasks under AppData for persistence. Later stages collected the victim IP address, created Dropbox log folders, monitored keystrokes and clipboard data, and wrote keylogging output to version.xml before sending it to a C2 endpoint under gbi????.com. The report provides representative file paths and hashes for version103.vbs, w{random}.ps1, and the final payload.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.dropboxapi.com/oaut… 2023-12-29 2025-09-03
HASH dce864eabfbd6445682a4671a2fee1a9 2023-12-29 2024-04-17
DOMAIN dddon.kr 2023-12-29 2024-04-17
HASH 66498ffe232da5691e0fb23d2b00c933 2023-12-29 2023-12-29
HASH 7649972a60a64258c3d484cca7d6464d 2023-12-29 2023-12-29
URL http://dddon.kr/doc/nase/docx/1… 2023-12-29 2023-12-29

Related Reports

« Back