생일 축하 내용으로 위장한 악성 한글 문서 (OLE 개체)
2022-08-23 • Ahnlab • Malicious Hangul document disguised as happy birthday content (OLE object) •
AhnLab analyzed a malicious Hangul document chain that uses VBScript downloaders and OLE-linked execution to stage additional files under %APPDATA% and Windows theme paths. The initial scripts retrieve content from datkka.atwebpages[.]com, datarium.epizy[.]com, and a Naver Mail download link, then register a scheduled task to run every 30 minutes. The HWP lure drops HappyBirthday.vbs, which attempts to download and execute another script from driver.googledocs.cloudns[.]nz. The document author metadata references a South Korean peace education platform, and the report assesses the lure was likely crafted for a target connected to North Korea-related individuals, but it does not attribute the activity to a DPRK actor.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6083a1af637d9dd2b2a16538a17e1f45 | 2022-08-23 | 2022-09-14 |
| HASH | ca2917006eb29171c9e5f374e789f53a | 2022-08-23 | 2022-09-14 |
| URL | https://driver.googledocs.cloud… | 2022-08-23 | 2022-09-14 |
| DOMAIN | driver.googledocs.cloudns.nz | 2022-08-23 | 2022-09-14 |
| HASH | 7c38b40ec19609f32de2a70d409c38b0 | 2022-08-23 | 2022-08-23 |
| HASH | d86d57c1d8670d510e7b7a1ad7db9fd2 | 2022-08-23 | 2022-08-23 |
| HASH | 60d117f5cb7b0f8133967ec535c85c6a | 2022-08-23 | 2022-08-23 |
| URL | https://datarium.epizy.com/2vbs | 2022-08-23 | 2022-08-23 |
| URL | http://datarium.epizy.com/2vbs | 2022-08-23 | 2022-08-23 |
| URL | http://datkka.atwebpages.com/2v… | 2022-08-23 | 2022-08-23 |
| URL | http://datkka.atwebpages.com/mal | 2022-08-23 | 2022-08-23 |
| URL | http://datkka.atwebpages.com/do… | 2022-08-23 | 2022-08-23 |
| DOMAIN | datarium.epizy.com | 2022-08-23 | 2022-08-23 |
| DOMAIN | datkka.atwebpages.com | 2022-08-23 | 2022-08-23 |