생일 축하 내용으로 위장한 악성 한글 문서 (OLE 개체)

2022-08-23 Ahnlab Malicious Hangul document disguised as happy birthday content (OLE object)

https://asec.ahnlab.com/ko/37974/

Thumbnail for 생일 축하 내용으로 위장한 악성 한글 문서 (OLE 개체)

AhnLab analyzed a malicious Hangul document chain that uses VBScript downloaders and OLE-linked execution to stage additional files under %APPDATA% and Windows theme paths. The initial scripts retrieve content from datkka.atwebpages[.]com, datarium.epizy[.]com, and a Naver Mail download link, then register a scheduled task to run every 30 minutes. The HWP lure drops HappyBirthday.vbs, which attempts to download and execute another script from driver.googledocs.cloudns[.]nz. The document author metadata references a South Korean peace education platform, and the report assesses the lure was likely crafted for a target connected to North Korea-related individuals, but it does not attribute the activity to a DPRK actor.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6083a1af637d9dd2b2a16538a17e1f45 2022-08-23 2022-09-14
HASH ca2917006eb29171c9e5f374e789f53a 2022-08-23 2022-09-14
URL https://driver.googledocs.cloud… 2022-08-23 2022-09-14
DOMAIN driver.googledocs.cloudns.nz 2022-08-23 2022-09-14
HASH 7c38b40ec19609f32de2a70d409c38b0 2022-08-23 2022-08-23
HASH d86d57c1d8670d510e7b7a1ad7db9fd2 2022-08-23 2022-08-23
HASH 60d117f5cb7b0f8133967ec535c85c6a 2022-08-23 2022-08-23
URL https://datarium.epizy.com/2vbs 2022-08-23 2022-08-23
URL http://datarium.epizy.com/2vbs 2022-08-23 2022-08-23
URL http://datkka.atwebpages.com/2v… 2022-08-23 2022-08-23
URL http://datkka.atwebpages.com/mal 2022-08-23 2022-08-23
URL http://datkka.atwebpages.com/do… 2022-08-23 2022-08-23
DOMAIN datarium.epizy.com 2022-08-23 2022-08-23
DOMAIN datkka.atwebpages.com 2022-08-23 2022-08-23

Related Reports

« Back