사례비 지급 내용으로 위장한 OneNote 악성코드 (Kimsuky)

2023-03-20 Ahnlab OneNote malware disguised as reward payment (Kimsuky)

https://asec.ahnlab.com/ko/49843/

Thumbnail for 사례비 지급 내용으로 위장한 OneNote 악성코드 (Kimsuky)

AhnLab ASEC reported a Kimsuky OneNote malware campaign disguised as reward-payment paperwork, extending the group’s recent use of CHM and LNK delivery formats. The OneNote lure appeared to contain a Korean HWP privacy-agreement document, but the clickable area hid a personal.vbs object that dropped and ran from a temporary path. The decoded script contacted hxxp://delps.scienceontheweb.net/ital/info/list.php?query=1 and used PowerShell to fetch a decoy personal.hwp from the same host, matching infrastructure and behavior previously seen in related Kimsuky document attacks. ASEC identified the OneNote hash aa756b20170aa0869d6f5d5b5f1b7c37 and VBS hash f2a0e92b80928830704a00c91df87644 as key indicators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN delps.scienceontheweb.net 2023-03-17 2024-12-16
HASH aa756b20170aa0869d6f5d5b5f1b7c37 2023-03-17 2023-05-24
HASH f2a0e92b80928830704a00c91df87644 2023-03-17 2023-05-24
URL http://delps.scienceontheweb.ne… 2023-03-17 2023-03-20
URL http://delps.scienceontheweb.ne… 2023-03-17 2023-03-20

Related Actors

Related Reports

« Back