코인 및 투자 관련 내용으로 위장한 악성코드 유포 중

2023-07-31 Ahnlab Spreading malware disguised as coin and investment-related content

https://asec.ahnlab.com/ko/55646/

Thumbnail for 코인 및 투자 관련 내용으로 위장한 악성코드 유포 중

ASEC observed malware disguised as cryptocurrency exchange and investment material, with User-Agent artifacts leading it to assess Kimsuky involvement. The campaign used SFX executables with Word/PDF icons to open decoy asset-management or coin-exchange documents while invoking mshta.exe against partner24.kr script paths. A related macro Word document copied wscript.exe to AppData as word.exe, downloaded Base64-encoded script content from partner24.kr/mokozy/hope/kk.php, wrote it as set.sl, and launched it with VBScript. Although the final payload was unavailable during analysis, the delivery chain could support information theft or additional malware download; ASEC listed partner24.kr URLs and MD5 hashes as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b6614471ebf288689d33808c376540e1 2023-07-31 2023-08-09
HASH 8a5fd1e9c9841ff0253b2a6f1e533d0e 2023-07-31 2023-08-09
HASH 17daf3ea7b80ee95792d4b3332a3390d 2023-07-31 2023-08-09
HASH 002105e21f1bddf68e59743c440e416a 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09

Related Actors

Related Reports

« Back