유럽 연합(EU)를 겨낭한것으로 추정 되는 라자루스 에서 만든 워드 악성코드-Interview.doc(2023.4.28)
2023-05-11 • Sakai • Word malware created by Lazarus that is believed to be targeting the European Union (EU) - Interview.doc (2023.4.28) •
The Korean analysis attributes a malicious Word document named “Interview.doc” to Lazarus activity suspected of targeting the European Union and lists hashes for the sample. The lure content presents a GDPR-themed document with cryptocurrency interview questions, and the macro creates and launches a shortcut that invokes mshta through a Bitly URL redirecting to share.googlefiledrive[.]com:8080. The source includes the VBA AutoOpen macro flow, downloader behavior, and antivirus detections, making the report useful for tracking Lazarus document-lure tradecraft, mshta/shortener-based delivery, and crypto-themed targeting rather than a confirmed victim compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d21add8bee4feefe812b0c16a6a541b… | 2023-05-11 | 2023-05-11 |
| HASH | 69ef7c4cb3849283c03eaa593b02ebb… | 2023-05-11 | 2023-05-11 |
| HASH | 292fbbf7e2ab20b12f4f2c0464a5b774 | 2023-05-11 | 2023-05-11 |
| URL | http://share.googlefiledrive.co… | 2023-05-11 | 2023-05-11 |
| URL | http://share.googlefiledrive.co… | 2023-05-11 | 2023-05-11 |
| DOMAIN | t.ly | 2020-09-25 | 2023-05-11 |
| DOMAIN | share.googlefiledrive.com | 2020-08-18 | 2023-05-11 |