[주의] '2차 북미정상회담' 내용의 한글취약점 문서
2019-02-21 • Ahnlab • [Caution] Hangul vulnerability document related to ‘2nd North Korea-US Summit' •
AhnLab ASEC observed malicious Hangul HWP documents circulating with content related to the upcoming second U.S.–North Korea summit. The documents contained a vulnerable EPS object whose shellcode is decoded with a one-byte XOR key and executed through the normal gswin32c.exe EPS handler on unpatched systems. The shellcode injects into Internet Explorer and attempts to download and run a second-stage DLL from itoassn.mireene.co.kr/shop/shop/mail/com/mun/down[.]php. AhnLab detected the HWP document and downloaded DLL as Trojan/Win32.Hwdoor.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://itoassn.mireene.co.kr/sh… | 2019-02-21 | 2019-02-21 |
| DOMAIN | itoassn.mireene.co.kr | 2019-02-21 | 2019-02-21 |
Related Reports
2026-05-27 •
50% Match
#Kimsuky
#Phishing
#LNK
#MeshAgent
#T1140
#T1115
#T1056.001
#T1027
#T1204.002
#T1566.001
#T1059.001
#T1105
#T1055
#T1497.003
#T1218.005
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab