새해 오피니언 언론 칼럼 위장 해킹 분석
2024-02-21 • Genians • New Year's Opinion Media Column Disguised Hacking Analysis •
Genian Security Center analyzed a January 2024 spear-phishing case that used a real New Year opinion column as the lure for Korean targets. The email delivered a password-protected ZIP containing a double-extension LNK disguised with a WordPad icon, then ran PowerShell to fetch scripts and a decoy RTF from Google Drive. The chain registered a hidden scheduled task named MicrosoftEdgeUpdateVersion and used manipulated Gzip data for defense evasion. The source ties the infrastructure to a Google Drive account named "fox tian" and the email tianfox67@gmail[.]com, with Genian EDR detection logic presented as the response path.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 27.255.75.158 | 2024-02-21 | 2024-03-05 |
| HASH | 92a18b9ac4945b444466b9950cb83e10 | 2024-02-21 | 2024-02-21 |
| HASH | ade57773e415db6265815df636aa83e9 | 2024-02-21 | 2024-02-21 |
| HASH | 14f97f5f286b1be0ca7213218b478466 | 2024-02-21 | 2024-02-21 |
| HASH | 2a40543f5b4b8cc1f4bd8993df44708e | 2024-02-21 | 2024-02-21 |
| HASH | 9e8bb11a8159ea5135def3895e7a5817 | 2024-02-21 | 2024-02-21 |
| HASH | 9732af12223214e121b0e693b2ab4e2c | 2024-02-21 | 2024-02-21 |
| HASH | f32653ec5e26ad7da610dfc194fb66ba | 2024-02-21 | 2024-02-21 |
| HASH | d94c3dffcffcf8591a8630a893deff5f | 2024-02-21 | 2024-02-21 |
| HASH | ec146031edfe94b2965d32b384a4b54f | 2024-02-21 | 2024-02-21 |
| HASH | bd07301e0b028887d61337f62ff24062 | 2024-02-21 | 2024-02-21 |
| HASH | 1e25fed1dab0e2e4651fc51db806a8b9 | 2024-02-21 | 2024-02-21 |
| [email protected] | 2024-02-21 | 2024-02-21 | |
| DOMAIN | taxservice.p-e.kr | 2024-02-21 | 2024-02-21 |
| DOMAIN | naveralarm.com | 2024-02-21 | 2024-02-21 |
| DOMAIN | countrysvc.p-e.kr | 2024-02-21 | 2024-02-21 |
| DOMAIN | nidnaver.info | 2024-02-21 | 2024-02-21 |
| DOMAIN | naveralert.com | 2024-02-21 | 2024-02-21 |
| DOMAIN | upbit-service.p-e.kr | 2024-02-21 | 2024-02-21 |
| DOMAIN | upbit2024.r-e.kr | 2024-02-21 | 2024-02-21 |
| DOMAIN | navecorps.com | 2024-02-21 | 2024-02-21 |
| DOMAIN | navercafe.info | 2024-02-21 | 2024-02-21 |
| IPv4 | 27.255.81.113 | 2024-02-21 | 2024-02-21 |
| IPv4 | 61.97.251.248 | 2024-02-21 | 2024-02-21 |
| IPv4 | 159.100.29.38 | 2024-02-21 | 2024-02-21 |
| IPv4 | 27.255.81.77 | 2024-02-21 | 2024-02-21 |
| IPv4 | 27.255.81.73 | 2024-02-21 | 2024-02-21 |
| IPv4 | 27.255.75.153 | 2024-02-21 | 2024-02-21 |
| IPv4 | 27.255.81.111 | 2024-02-21 | 2024-02-21 |