세금 고지서로 위장한 정보 탈취 악성코드

2025-05-27 Hauri ( Document No : DT-20250527-001 )

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=76

Attachments

2025-05-27상세분석보고서세금고지서로위장한정보탈취악성코드.pdf (1 MB)

Hauri analyzed a tax-notice-themed LNK attack that launches mshta.exe to retrieve txjyh.hta from cdn.glitch.global and execute an information-stealing chain. The HTA displays a tax.pdf decoy and branches on Windows Defender status: Defender-enabled hosts decode zip.log into pipe.zip and run obfuscated script malware, while Defender-disabled hosts execute v3.hta and load sys.dll through rundll32. The script path registers C:\%localappdata%\pipe\1.vbs as WindowsSecurityCheck under HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence. The malware collects execution time, privileges, OS, CPU, disk, volume, network adapter, process data, recent files, browser cookies, credentials, bookmarks, documents, archives, images, email files, logs, and cryptocurrency wallet-related artifacts. Stolen data is compressed into init.zip or related log archives and sent to lntzz.hopto.org/service3 or qokfqb.freedynamicdns.org/service2, with support for keylogging and additional payload execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 67f16738ac5099d439d2f22c10b80bf5 2025-05-27 2025-05-27
HASH 827206241502d2f0cd564446a29f19d5 2025-05-27 2025-05-27
HASH 856580d71b13d2399da8207616921dad 2025-05-27 2025-05-27
HASH 7928c436d113c5204f2a1d2e0b0d6c36 2025-05-27 2025-05-27
HASH 63958f690533d9b9bf3daf264c0fe049 2025-05-27 2025-05-27
HASH f3175cf220edaa4942824f6dff78f053 2025-05-27 2025-05-27
HASH 6219af78a2d79adfe6313d6c75df4f6b 2025-05-27 2025-05-27
HASH 2cd475395f4ee65c2c2337c112916997 2025-05-27 2025-05-27
HASH 5d6baf533643c57a0022b4e0aac7cef3 2025-05-27 2025-05-27
HASH be171953b71c6636e40a01fcf780ba97 2025-05-27 2025-05-27
HASH a375c660613cbdea08ff47dd13506fc8 2025-05-27 2025-05-27
HASH 9aa925d86b0a176eeb69aa0e9f24c418 2025-05-27 2025-05-27
URL https://cdn.glitch.global/b33b4… 2025-05-27 2025-05-27
URL http://lntzz.hopto.org/service3/ 2025-05-27 2025-05-27
URL http://cdn.glitch.global/b33b49… 2025-05-27 2025-05-27
URL http://cdn.glitch.global/b33b49… 2025-05-27 2025-05-27
DOMAIN lntzz.hopto.org 2025-05-27 2025-05-27
DOMAIN qokfqb.freedynamicdns.org 2025-05-27 2025-05-27
DOMAIN cdn.glitch.global 2025-03-28 2025-05-27

Related Reports

« Back