정상 엑셀/워드 문서로 위장한 악성 코드

2021-05-24 Ahnlab Malicious code disguised as a normal Excel/Word document

https://asec.ahnlab.com/ko/23396/

Thumbnail for 정상 엑셀/워드 문서로 위장한 악성 코드

AhnLab describes malicious Excel and Word documents disguised as normal Korean business or event files, including card-company themed spreadsheets and forum-related documents that prompt users to enable macros. Once macros run, the samples fetch additional PowerShell or script payloads from infrastructure such as manstr.myartsonline.com, rukagu.mypressonline.com, and warms.atwebpages.com, then collect host information, download further components, and attempt persistence. Follow-on payloads include Alzip-themed artifacts and a pagefile.sys component that gathers system data, kills security-related processes, checks for VMware artifacts, and exfiltrates data by email. The source attributes the files to the same operator based on shared macro code and behavior, but does not make a DPRK attribution in the excerpt.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://rukagu.mypressonline.com… 2021-05-24 2021-09-01
DOMAIN rukagu.mypressonline.com 2021-05-24 2021-09-01
EMAIL [email protected] 2021-05-24 2021-05-24
URL http://warms.atwebpages.com/rh/… 2021-05-24 2021-05-24
URL http://warms.atwebpages.com/rh/… 2021-05-24 2021-05-24
URL http://warms.atwebpages.com/rh/… 2021-05-24 2021-05-24
URL http://manstr.myartsonline.com/… 2021-05-24 2021-05-24
URL http://warms.atwebpages.com/rh/… 2021-05-24 2021-05-24
DOMAIN wariii.mypressonline.com 2021-05-24 2021-05-24
DOMAIN warms.atwebpages.com 2021-05-24 2021-05-24
DOMAIN manstr.myartsonline.com 2021-05-24 2021-05-24

Related Reports

« Back