악성 OLE 개체가 삽입된 한글 문서 주의

2023-10-27 Ahnlab Warning about Hangul documents containing malicious OLE objects

https://asec.ahnlab.com/ko/58043/

Thumbnail for 악성 OLE 개체가 삽입된 한글 문서 주의

AhnLab ASEC analyzed malicious Hangul documents aimed at people in defense, media, unification, education, and broadcasting related fields. One cluster used oversized embedded OLE objects to make nearly any click in the document trigger a connection to attacker URLs such as host.sharingdocument[.]one or mail.smartprivacyc[.]com, with per-document parameters suggesting targeted delivery. A second cluster embedded batch and text files that launched PowerShell, fetched obfuscated scripts from a GitHub repository, collected recent file lists, network configuration, and process data, and uploaded the results to an FTP server at plm.myartsonline[.]com. The same script chain created startup persistence through an LNK file and thumbs.log so the PowerShell downloader would run again after reboot.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2f0a67b719d8303c0ec7cc9057ed8411 2023-10-27 2023-11-01
HASH a242741873637fdac8f69f2ffdba47bc 2023-10-27 2023-11-01
HASH 2ef182bced72da507d2e403ab9db3c9f 2023-10-27 2023-11-01
HASH 0217e70fd7bc3a65ee0f2dd60ff85fbf 2023-10-27 2023-11-01
HASH c16796909d5feea709d99e306f7e9975 2023-10-27 2023-11-01
HASH 8cafe74f03605a9bfaea5081b3ed0fc2 2023-10-27 2023-11-01
HASH 2773acee87413790e9ace99c536c78ad 2023-10-27 2023-11-01
HASH f416b44332b4fb394b4735634cb07ff2 2023-10-27 2023-11-01
HASH 77edb140b86596eabe3602bb7febb997 2023-10-27 2023-11-01
HASH 1061425d7e3d054a79f9294a2118b5da 2023-10-27 2023-11-01
HASH af5bbab33f934dc016fc1aa0d910820e 2023-10-27 2023-11-01
HASH 4934226f319d82ae092ada2525a7feb5 2023-10-27 2023-11-01
HASH 7284a6376aa79a2384f797769b7ce086 2023-10-27 2023-11-01
HASH 7f3a30525b9324a2aeb32a9018df944f 2023-10-27 2023-11-01
HASH 361237b6b385874f02f3724ae50d1522 2023-10-27 2023-11-01
HASH d5d395d90ccf9a7309f2f64169a2c019 2023-10-27 2023-11-01
URL http://mail.smartprivacyc.com/g… 2023-10-27 2023-11-01
URL http://host.sharingdocument.one… 2023-10-27 2023-11-01
DOMAIN host.sharingdocument.one 2023-10-27 2023-11-01
DOMAIN mail.smartprivacyc.com 2023-10-27 2023-11-01
DOMAIN plm.myartsonline.com 2023-10-27 2023-11-01

Related Reports

« Back