코로나바이러스 대응 긴급조회 한글문서 악성코드 유포
2020-04-02 • Ahnlab • Emergency inquiry on coronavirus response: Korean document spreading malicious code •
ASEC reported malicious HWP documents disguised as urgent COVID-19 response inquiries from Korean regional infection-control organizations, including Jeollanam-do and Incheon. Unlike common Office macro lures, these Hangul files embedded EPS content that used PowerShell to contact external URLs and download additional malware. The downloaded executable provided information-stealing and backdoor functions, sending collected system data to attacker-controlled C2 servers. AhnLab noted detection for both the HWP exploit and the Windows payload, and highlighted behavior-based detection for the malicious download and execution chain.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://www.kingsvc.cc/index.php | 2020-04-02 | 2020-05-29 |
| URL | http://www.sofa.rs/wp-admin/net… | 2020-04-02 | 2020-05-29 |
| HASH | 8451be72b75a38516e7ba7972729909e | 2020-04-02 | 2020-05-09 |
| URL | http://www.mbrainingevents.com/… | 2020-04-02 | 2020-04-15 |
| URL | http://www.afuocolento.it/wp-ad… | 2020-04-02 | 2020-04-15 |