원산지 조사 자율 점검표' 한글(HWP) 악성코드 유포
2020-07-24 • Ahnlab • HWP malware distributed as an origin investigation self-inspection checklist •
ASEC reporting describes a malicious HWP document containing EPS/PostScript content that executes shellcode and CMD commands. The lure appears to abuse a legitimate origin self-check form from a government legal-information source, while related activity used COVID-themed Excel lures. The embedded script behavior overlaps with a previously observed malicious Excel document, indicating reuse of delivery and execution tradecraft. Defenders should monitor for HWP/EPS exploitation chains, suspicious CMD execution from document processes, and follow-on payload retrieval.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://nextlevelliving.pro/wp-i… | 2020-07-24 | 2020-07-24 |
| URL | http://www.trebat.co/wp-content… | 2020-07-24 | 2020-07-24 |