유사한 도메인 형태의 External 링크를 사용하는 악성 워드 문서
2021-11-02 • Ahnlab • Malicious word document using external link with similar domain type •
AhnLab describes malicious Word documents that used external template links as an upstream stage before downloading macro-enabled documents and a PE backdoor. The observed chain began with a Word file containing a malicious XML external relationship to kr9235.atwebpages[.]com, then downloaded an obfuscated macro document that retrieved cvwiq.zip and executed the extracted wieb.dat DLL through rundll32.exe. ASEC notes that similar atwebpages[.]com infrastructure and kr[number] host patterns had been used by North Korea-linked attack groups in earlier document operations. The report highlights the technique’s use of protected and hidden document content to make the lure appear legitimate while the template and payload chain executes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | atwebpages.com | 2018-02-02 | 2024-09-05 |
| URL | http://schemas.openxmlformats.o… | 2020-03-20 | 2023-06-06 |
| URL | http://kr2959.atwebpages.com/vi… | 2021-11-02 | 2021-11-02 |
| URL | http://kr9235.atwebpages.com/vi… | 2021-11-02 | 2021-11-02 |
| URL | http://kr9235.atwebpages.com/vi… | 2021-11-02 | 2021-11-02 |
| URL | http://kr7593.atwebpages.com/vi… | 2021-11-02 | 2021-11-02 |
| URL | http://kr4952.atwebpages.com/vi… | 2021-11-02 | 2021-11-02 |
| DOMAIN | kr9235.atwebpages.com | 2021-11-02 | 2021-11-02 |
| DOMAIN | kr7593.atwebpages.com | 2021-11-02 | 2021-11-02 |
| DOMAIN | kr4952.atwebpages.com | 2021-11-02 | 2021-11-02 |
| DOMAIN | kr2959.atwebpages.com | 2021-07-26 | 2021-11-02 |