원산지 조사 자율 점검표' 한글(HWP) 악성코드 유포

2020-07-24 Ahnlab HWP malware distributed as an origin investigation self-inspection checklist

https://asec.ahnlab.com/1359

Thumbnail for 원산지 조사 자율 점검표' 한글(HWP) 악성코드 유포

ASEC reporting describes a malicious HWP document containing EPS/PostScript content that executes shellcode and CMD commands. The lure appears to abuse a legitimate origin self-check form from a government legal-information source, while related activity used COVID-themed Excel lures. The embedded script behavior overlaps with a previously observed malicious Excel document, indicating reuse of delivery and execution tradecraft. Defenders should monitor for HWP/EPS exploitation chains, suspicious CMD execution from document processes, and follow-on payload retrieval.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://nextlevelliving.pro/wp-i… 2020-07-24 2020-07-24
URL http://www.trebat.co/wp-content… 2020-07-24 2020-07-24

Related Reports

« Back