취약점 한글파일을 이용한 MBR 파괴기능의 악성코드 등장

2014-12-10 Ahnlab Appearance of malicious code with MBR destruction function using vulnerability Hangul file

http://asec.ahnlab.com/1015

Thumbnail for 취약점 한글파일을 이용한 MBR 파괴기능의 악성코드 등장

AhnLab analyzed nine malicious Hangul Word Processor documents that used a known HWP vulnerability and were reportedly distributed as email attachments to specific recipients. Each document carried the same malicious file, which installed a DLL under the system directory as a randomly named Windows service and included both backdoor-style behavior and destructive functions. The payload used a registry value and local system time check to decide when to overwrite the MBR, replacing 512 bytes and showing a “Who Am I?” message on reboot. It also searched drive letters A through Z for selected file extensions and truncated matching files to 4 KB filled with null bytes. The report provides MD5 hashes for the exploit documents and the Win32 destroyer payload, supporting defensive validation and detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 54783422cfd7029a26a3f3f5e9087d8a 2014-12-10 2019-03-04
HASH f09ea2a841114121f32211faac553e1b 2014-12-10 2014-12-23
HASH 33874577bf54d3c209925c9def880eb9 2014-12-10 2014-12-23
HASH 9daf088fe4c9a9580216e98dbb7d1fca 2014-12-10 2014-12-23
HASH 3ba8a6815f828dfc518a0bdbd27bba5b 2014-12-10 2014-12-23
HASH b5b6e93ab27cec75f07af2a3a6a40926 2014-12-10 2014-12-23
HASH ead682b889218979b1f2f1527227af9b 2014-12-10 2014-12-23
HASH 800866bbab514657969996210bcf727b 2014-12-10 2014-12-23
HASH af792a34548a2038f034ea9a6ff0639a 2014-12-10 2014-12-23
HASH 3ec69ee7135272e5bed3ea5378ade6ee 2014-12-10 2014-12-23

Related Reports

« Back