코로나19 지원금 관련 ‘개인정보 수집 동의서’ 본문 내용의 악성 한글(HWP) 파일
2021-10-19 • Ahnlab • Malicious Korean (HWP) file in the main text of the ‘Personal Information Collection Consent' related to COVID-19 support funds •
ASEC analyzed a malicious HWP document disguised as a COVID-19 emergency relief personal-information consent form, apparently edited from a legitimate document and last modified in early October. The file contains an encoded EPS/PostScript object that decrypts to shellcode, reusing components linked to a recent airline cover-letter-themed RTF and infrastructure seen in a 2019 malicious HWP case. The shellcode was designed to retrieve additional payloads from gozdeelektronik[.]net paths ending in movie.png and movie.jpg and inject them into explorer.exe, although the payloads were unavailable during analysis. The source notes that the EPS vulnerability was patched in 2017, limiting execution on fully updated HWP installations, and AhnLab detects the activity as Malware/MDP.Behavior.M2411.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://gozdeelektronik.net/wp-… | 2019-06-20 | 2021-10-28 |
| URL | https://gozdeelektronik.net/wp-… | 2019-06-20 | 2021-10-28 |
| DOMAIN | gozdeelektronik.net | 2019-06-20 | 2021-10-28 |