분석 멈춰!! 나 문서파일이야
2021-06-03 • Sands Lab • Stop analyzing!! I am a document file •
https://drive.google.com/file/d/1FYpi3CyPTfj0zslkcj4JkIEITkubiTNn/view
Attachments
This Korean malware analysis covers a malicious document named as an International Constitution Day forum file that likely used phishing to reach a broad target set. Enabling content runs obfuscated macros that contact rukagu.mypressonline.com, fetch /le/yj.txt, and execute it with PowerShell. The script changes PowerShell execution policy, creates an AhnLab themed directory and persistence key, collects system information into a decoy HWP file, uploads it to C2, and attempts to download and decrypt a later payload. The authors tie the activity to a previously observed attack group based on script structure and shared C2 IP infrastructure.