특정 항공사 자소서로 위장한 RTF 악성코드

2021-10-13 Ahnlab RTF malware disguised as a specific airline resume

https://asec.ahnlab.com/ko/27678/

Thumbnail for 특정 항공사 자소서로 위장한 RTF 악성코드

ASEC analyzed an RTF malware sample disguised as an airline cover-letter or resume document and created in early October 2021. The file exploited the Microsoft Equation Editor vulnerability CVE-2017-11882 and, if triggered, attempted to download additional payloads from gozdeelektronik[.]net paths ending in movie.png and movie.jpg. The source says those URLs were inactive during analysis, but the same infrastructure had been used by a 2019 malicious EPS/HWP case, suggesting reuse by the same group. ASEC notes that external Twitter reporting associated the RTF activity with Lazarus, but the article itself treats the attribution cautiously.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://gozdeelektronik.net/wp-… 2019-06-20 2021-10-28
URL https://gozdeelektronik.net/wp-… 2019-06-20 2021-10-28
DOMAIN gozdeelektronik.net 2019-06-20 2021-10-28
HASH dd8bb1686f16924ac797620092776022 2021-10-13 2021-10-13

Related Reports

« Back