타겟형 공격 <사례비지급 의뢰서> 악성 워드문서 유포

2021-06-09 Ahnlab Targeted attack <Request for payment of compensation> Malicious word document distributed

https://asec.ahnlab.com/ko/24220/

Thumbnail for 타겟형 공격 <사례비지급 의뢰서> 악성 워드문서 유포

AhnLab analyzed a renewed targeted malicious Word document campaign using a Korean “payment request” lure that had also appeared in earlier activity. The document’s VBA macro was stored with an HTML extension and only executed after the user typed in the document, creating and running VBS files named desktop.ini under %AppData% and %AppData%\Microsoft and adding an Internet Explorer startup shortcut for persistence. The script fetched attacker-hosted content from smyun0272.blogspot.com and exfiltrated reconnaissance data such as running services, Office Excel version, pinned taskbar shortcuts, user, OS, and file-path information to alyssalove.getenjoyment.net. AhnLab assessed the activity as tied to the same suspected North Korean actor behind related targeted Word documents that reused the unusual aaaaaaaaaaaa VBA function.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 811b42bb169f02d1b0b3527e2ca6c00… 2021-06-09 2021-11-10
URL http://ftcpark59.getenjoyment.n… 2021-06-09 2021-09-01
URL http://alyssalove.getenjoyment.… 2021-06-09 2021-09-01
DOMAIN alyssalove.getenjoyment.net 2021-06-09 2021-09-01
DOMAIN ftcpark59.getenjoyment.net 2021-03-26 2021-09-01

Related Reports

« Back