코인 및 투자 관련 내용으로 위장한 악성코드 유포 중
2023-07-31 • Ahnlab • Spreading malware disguised as coin and investment-related content •
ASEC observed malware disguised as cryptocurrency exchange and investment material, with User-Agent artifacts leading it to assess Kimsuky involvement. The campaign used SFX executables with Word/PDF icons to open decoy asset-management or coin-exchange documents while invoking mshta.exe against partner24.kr script paths. A related macro Word document copied wscript.exe to AppData as word.exe, downloaded Base64-encoded script content from partner24.kr/mokozy/hope/kk.php, wrote it as set.sl, and launched it with VBScript. Although the final payload was unavailable during analysis, the delivery chain could support information theft or additional malware download; ASEC listed partner24.kr URLs and MD5 hashes as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b6614471ebf288689d33808c376540e1 | 2023-07-31 | 2023-08-09 |
| HASH | 8a5fd1e9c9841ff0253b2a6f1e533d0e | 2023-07-31 | 2023-08-09 |
| HASH | 17daf3ea7b80ee95792d4b3332a3390d | 2023-07-31 | 2023-08-09 |
| HASH | 002105e21f1bddf68e59743c440e416a | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |