[주의] '2차 북미정상회담' 내용의 한글취약점 문서

2019-02-21 Ahnlab [Caution] Hangul vulnerability document related to ‘2nd North Korea-US Summit'

https://asec.ahnlab.com/1201

Thumbnail for [주의] '2차 북미정상회담' 내용의 한글취약점 문서

AhnLab ASEC observed malicious Hangul HWP documents circulating with content related to the upcoming second U.S.–North Korea summit. The documents contained a vulnerable EPS object whose shellcode is decoded with a one-byte XOR key and executed through the normal gswin32c.exe EPS handler on unpatched systems. The shellcode injects into Internet Explorer and attempts to download and run a second-stage DLL from itoassn.mireene.co.kr/shop/shop/mail/com/mun/down[.]php. AhnLab detected the HWP document and downloaded DLL as Trojan/Win32.Hwdoor.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://itoassn.mireene.co.kr/sh… 2019-02-21 2019-02-21
DOMAIN itoassn.mireene.co.kr 2019-02-21 2019-02-21

Related Reports

« Back