‘수출용 골드바 매매 계약서’로 위장한 악성 워드문서
2021-08-24 • Ahnlab • Malicious word document disguised as ‘export gold bar sales contract' •
ASEC analyzed a malicious Word document disguised as an export gold-bar sales contract and noted links to Kimsuky-related APT activity through the same document-protection password, 1qaz2wsx, used in earlier North Korea-themed malicious Word files. When the embedded macro runs, it removes the protected cover content and creates an XML file under the user’s Microsoft Templates path that is executed with wscript.exe. The document attempts to reach hxxp://regedit.onlinewebshop[.]net/hosteste/rownload/list.php?query=1 for follow-on activity, although the network endpoint was inactive at analysis time, and AhnLab detects the file as Downloader/DOC malware.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://regedit.onlinewebshop.ne… | 2021-08-24 | 2021-11-01 |
| DOMAIN | regedit.onlinewebshop.net | 2021-08-24 | 2021-11-01 |