취약점 한글파일을 이용한 MBR 파괴기능의 악성코드 등장
2014-12-10 • Ahnlab • Appearance of malicious code with MBR destruction function using vulnerability Hangul file •
AhnLab analyzed nine malicious Hangul Word Processor documents that used a known HWP vulnerability and were reportedly distributed as email attachments to specific recipients. Each document carried the same malicious file, which installed a DLL under the system directory as a randomly named Windows service and included both backdoor-style behavior and destructive functions. The payload used a registry value and local system time check to decide when to overwrite the MBR, replacing 512 bytes and showing a “Who Am I?” message on reboot. It also searched drive letters A through Z for selected file extensions and truncated matching files to 4 KB filled with null bytes. The report provides MD5 hashes for the exploit documents and the Win32 destroyer payload, supporting defensive validation and detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 54783422cfd7029a26a3f3f5e9087d8a | 2014-12-10 | 2019-03-04 |
| HASH | f09ea2a841114121f32211faac553e1b | 2014-12-10 | 2014-12-23 |
| HASH | 33874577bf54d3c209925c9def880eb9 | 2014-12-10 | 2014-12-23 |
| HASH | 9daf088fe4c9a9580216e98dbb7d1fca | 2014-12-10 | 2014-12-23 |
| HASH | 3ba8a6815f828dfc518a0bdbd27bba5b | 2014-12-10 | 2014-12-23 |
| HASH | b5b6e93ab27cec75f07af2a3a6a40926 | 2014-12-10 | 2014-12-23 |
| HASH | ead682b889218979b1f2f1527227af9b | 2014-12-10 | 2014-12-23 |
| HASH | 800866bbab514657969996210bcf727b | 2014-12-10 | 2014-12-23 |
| HASH | af792a34548a2038f034ea9a6ff0639a | 2014-12-10 | 2014-12-23 |
| HASH | 3ec69ee7135272e5bed3ea5378ade6ee | 2014-12-10 | 2014-12-23 |