정책결정 의견수렴 요청으로 위장한 피싱메일 주의

2022-03-24 Hauri Caution: Phishing Email Disguised as a Request for Opinions on Policy Decisions

https://www.hauri.co.kr/security/issue_view.html?intSeq=414&page=1

Thumbnail for 정책결정 의견수렴 요청으로 위장한 피싱메일 주의

Hauri reported phishing emails in South Korea disguised as requests for public input on internet address policy decisions. The emails encouraged recipients to open a password-protected document and enable macros after entering a password supplied in the message. Once macros were enabled, the document contacted a C2 server to download encoded PE data, decode it, and execute it from document memory. The listed C2 path was http://1xJOiKZd[.]naveicoipa[.]tech/ACMS/Cjtpp17D/Cjtpp17D32.acm, though the server was no longer reachable at analysis time. The campaign matters because it paired policy-themed social engineering with macro-based payload retrieval against domestic users.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN 1xjoikzd.naveicoipa.tech 2022-03-24 2022-04-11
URL http://1xJOiKZd.naveicoipa.tech… 2022-03-24 2022-03-24

Related Reports

« Back