유럽 연합(EU)를 겨낭한것으로 추정 되는 라자루스 에서 만든 워드 악성코드-Interview.doc(2023.4.28)

2023-05-11 Sakai Word malware created by Lazarus that is believed to be targeting the European Union (EU) - Interview.doc (2023.4.28)

https://wezard4u.tistory.com/6437

Thumbnail for 유럽 연합(EU)를 겨낭한것으로 추정 되는 라자루스 에서 만든 워드 악성코드-Interview.doc(2023.4.28)

The Korean analysis attributes a malicious Word document named “Interview.doc” to Lazarus activity suspected of targeting the European Union and lists hashes for the sample. The lure content presents a GDPR-themed document with cryptocurrency interview questions, and the macro creates and launches a shortcut that invokes mshta through a Bitly URL redirecting to share.googlefiledrive[.]com:8080. The source includes the VBA AutoOpen macro flow, downloader behavior, and antivirus detections, making the report useful for tracking Lazarus document-lure tradecraft, mshta/shortener-based delivery, and crypto-themed targeting rather than a confirmed victim compromise.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d21add8bee4feefe812b0c16a6a541b… 2023-05-11 2023-05-11
HASH 69ef7c4cb3849283c03eaa593b02ebb… 2023-05-11 2023-05-11
HASH 292fbbf7e2ab20b12f4f2c0464a5b774 2023-05-11 2023-05-11
URL http://share.googlefiledrive.co… 2023-05-11 2023-05-11
URL http://share.googlefiledrive.co… 2023-05-11 2023-05-11
DOMAIN t.ly 2020-09-25 2023-05-11
DOMAIN share.googlefiledrive.com 2020-08-18 2023-05-11

Related Reports

« Back