제품소개서로 위장한 악성 워드 문서
2022-03-14 • Ahnlab • Malicious Word Document Disguised as a Product Introduction •
ASEC analyzed a malicious Word document disguised as a product introduction that appeared to target South Korean logistics or shopping-related organizations. The document reused metadata and macro-enablement lures from a prior information-theft Word campaign, suggesting the attacker modified an existing template and continued the same delivery pattern. When macros executed, the document downloaded BAT, VBS, CAB, and a second Word file from manage-box.com, staged scripts under C:\Users\Public\Documents, registered persistence through HKCU Run, and used safemaners.com for additional downloads and exfiltration. The script chain collected directory listings, IP information, task lists, and system information, and ASEC noted the attacker redirected malicious domains to Naver Mail to make infrastructure appear legitimate.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://manage-box.com/ord03/vbs… | 2022-03-14 | 2022-03-14 |
| URL | http://manage-box.com/doc03/tem… | 2022-03-14 | 2022-03-14 |
| URL | http://safemaners.com/upl11/upl… | 2022-03-14 | 2022-03-14 |
| URL | http://manage-box.com/ord03/no0… | 2022-03-14 | 2022-03-14 |
| URL | http://safemaners.com/dow11/%CO… | 2022-03-14 | 2022-03-14 |
| URL | http://manage-box.com/ord03 | 2022-03-14 | 2022-03-14 |
| DOMAIN | safemaners.com | 2022-03-14 | 2022-03-14 |
| DOMAIN | manage-box.com | 2022-03-14 | 2022-03-14 |