‘수출용 골드바 매매 계약서’로 위장한 악성 워드문서

2021-08-24 Ahnlab Malicious word document disguised as ‘export gold bar sales contract'

https://asec.ahnlab.com/ko/26609/

Thumbnail for ‘수출용 골드바 매매 계약서’로 위장한 악성 워드문서

ASEC analyzed a malicious Word document disguised as an export gold-bar sales contract and noted links to Kimsuky-related APT activity through the same document-protection password, 1qaz2wsx, used in earlier North Korea-themed malicious Word files. When the embedded macro runs, it removes the protected cover content and creates an XML file under the user’s Microsoft Templates path that is executed with wscript.exe. The document attempts to reach hxxp://regedit.onlinewebshop[.]net/hosteste/rownload/list.php?query=1 for follow-on activity, although the network endpoint was inactive at analysis time, and AhnLab detects the file as Downloader/DOC malware.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://regedit.onlinewebshop.ne… 2021-08-24 2021-11-01
DOMAIN regedit.onlinewebshop.net 2021-08-24 2021-11-01

Related Actors

Related Reports

« Back