분석 멈춰!! 나 문서파일이야

2021-06-03 Sands Lab Stop analyzing!! I am a document file

https://drive.google.com/file/d/1FYpi3CyPTfj0zslkcj4JkIEITkubiTNn/view

Attachments

210603_MWS_상세분석보고서_제헌절_국제학술포럼.pdf (1 MB)

Thumbnail for 분석 멈춰!! 나 문서파일이야

This Korean malware analysis covers a malicious document named as an International Constitution Day forum file that likely used phishing to reach a broad target set. Enabling content runs obfuscated macros that contact rukagu.mypressonline.com, fetch /le/yj.txt, and execute it with PowerShell. The script changes PowerShell execution policy, creates an AhnLab themed directory and persistence key, collects system information into a decoy HWP file, uploads it to C2, and attempts to download and decrypt a later payload. The authors tie the activity to a previously observed attack group based on script structure and shared C2 IP infrastructure.

Related Actors

Related Reports

« Back