유사한 도메인 형태의 External 링크를 사용하는 악성 워드 문서

2021-11-02 Ahnlab Malicious word document using external link with similar domain type

https://asec.ahnlab.com/ko/28284/

Thumbnail for 유사한 도메인 형태의 External 링크를 사용하는 악성 워드 문서

AhnLab describes malicious Word documents that used external template links as an upstream stage before downloading macro-enabled documents and a PE backdoor. The observed chain began with a Word file containing a malicious XML external relationship to kr9235.atwebpages[.]com, then downloaded an obfuscated macro document that retrieved cvwiq.zip and executed the extracted wieb.dat DLL through rundll32.exe. ASEC notes that similar atwebpages[.]com infrastructure and kr[number] host patterns had been used by North Korea-linked attack groups in earlier document operations. The report highlights the technique’s use of protected and hidden document content to make the lure appear legitimate while the template and payload chain executes.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN atwebpages.com 2018-02-02 2024-09-05
URL http://schemas.openxmlformats.o… 2020-03-20 2023-06-06
URL http://kr2959.atwebpages.com/vi… 2021-11-02 2021-11-02
URL http://kr9235.atwebpages.com/vi… 2021-11-02 2021-11-02
URL http://kr9235.atwebpages.com/vi… 2021-11-02 2021-11-02
URL http://kr7593.atwebpages.com/vi… 2021-11-02 2021-11-02
URL http://kr4952.atwebpages.com/vi… 2021-11-02 2021-11-02
DOMAIN kr9235.atwebpages.com 2021-11-02 2021-11-02
DOMAIN kr7593.atwebpages.com 2021-11-02 2021-11-02
DOMAIN kr4952.atwebpages.com 2021-11-02 2021-11-02
DOMAIN kr2959.atwebpages.com 2021-07-26 2021-11-02

Related Reports

« Back