타겟형 공격 <사례비지급 의뢰서> 악성 워드문서 유포
2021-06-09 • Ahnlab • Targeted attack <Request for payment of compensation> Malicious word document distributed •
AhnLab analyzed a renewed targeted malicious Word document campaign using a Korean “payment request” lure that had also appeared in earlier activity. The document’s VBA macro was stored with an HTML extension and only executed after the user typed in the document, creating and running VBS files named desktop.ini under %AppData% and %AppData%\Microsoft and adding an Internet Explorer startup shortcut for persistence. The script fetched attacker-hosted content from smyun0272.blogspot.com and exfiltrated reconnaissance data such as running services, Office Excel version, pinned taskbar shortcuts, user, OS, and file-path information to alyssalove.getenjoyment.net. AhnLab assessed the activity as tied to the same suspected North Korean actor behind related targeted Word documents that reused the unusual aaaaaaaaaaaa VBA function.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 811b42bb169f02d1b0b3527e2ca6c00… | 2021-06-09 | 2021-11-10 |
| URL | http://ftcpark59.getenjoyment.n… | 2021-06-09 | 2021-09-01 |
| URL | http://alyssalove.getenjoyment.… | 2021-06-09 | 2021-09-01 |
| DOMAIN | alyssalove.getenjoyment.net | 2021-06-09 | 2021-09-01 |
| DOMAIN | ftcpark59.getenjoyment.net | 2021-03-26 | 2021-09-01 |