제품소개서로 위장한 악성 워드 문서

2022-03-14 Ahnlab Malicious Word Document Disguised as a Product Introduction

https://asec.ahnlab.com/ko/32532/

Thumbnail for 제품소개서로 위장한 악성 워드 문서

ASEC analyzed a malicious Word document disguised as a product introduction that appeared to target South Korean logistics or shopping-related organizations. The document reused metadata and macro-enablement lures from a prior information-theft Word campaign, suggesting the attacker modified an existing template and continued the same delivery pattern. When macros executed, the document downloaded BAT, VBS, CAB, and a second Word file from manage-box.com, staged scripts under C:\Users\Public\Documents, registered persistence through HKCU Run, and used safemaners.com for additional downloads and exfiltration. The script chain collected directory listings, IP information, task lists, and system information, and ASEC noted the attacker redirected malicious domains to Naver Mail to make infrastructure appear legitimate.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://manage-box.com/ord03/vbs… 2022-03-14 2022-03-14
URL http://manage-box.com/doc03/tem… 2022-03-14 2022-03-14
URL http://safemaners.com/upl11/upl… 2022-03-14 2022-03-14
URL http://manage-box.com/ord03/no0… 2022-03-14 2022-03-14
URL http://safemaners.com/dow11/%CO… 2022-03-14 2022-03-14
URL http://manage-box.com/ord03 2022-03-14 2022-03-14
DOMAIN safemaners.com 2022-03-14 2022-03-14
DOMAIN manage-box.com 2022-03-14 2022-03-14

Related Reports

« Back