코로나바이러스 대응 긴급조회 한글문서 악성코드 유포

2020-04-02 Ahnlab Emergency inquiry on coronavirus response: Korean document spreading malicious code

https://asec.ahnlab.com/1310

Thumbnail for 코로나바이러스 대응 긴급조회 한글문서 악성코드 유포

ASEC reported malicious HWP documents disguised as urgent COVID-19 response inquiries from Korean regional infection-control organizations, including Jeollanam-do and Incheon. Unlike common Office macro lures, these Hangul files embedded EPS content that used PowerShell to contact external URLs and download additional malware. The downloaded executable provided information-stealing and backdoor functions, sending collected system data to attacker-controlled C2 servers. AhnLab noted detection for both the HWP exploit and the Windows payload, and highlighted behavior-based detection for the malicious download and execution chain.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://www.kingsvc.cc/index.php 2020-04-02 2020-05-29
URL http://www.sofa.rs/wp-admin/net… 2020-04-02 2020-05-29
HASH 8451be72b75a38516e7ba7972729909e 2020-04-02 2020-05-09
URL http://www.mbrainingevents.com/… 2020-04-02 2020-04-15
URL http://www.afuocolento.it/wp-ad… 2020-04-02 2020-04-15

Related Reports

« Back