패스워드 파일로 위장하여 유포 중인 악성코드

2023-03-10 Ahnlab Malware distributed disguised as a password file

https://asec.ahnlab.com/ko/49180/

Thumbnail for 패스워드 파일로 위장하여 유포 중인 악성코드

AhnLab reports Korean-targeted malware distributed in archives that pair password-protected legitimate documents with files masquerading as password information. One CHM variant is assessed as likely tied to RedEyes/APT37/ScarCruft because it reuses commands seen in the group’s M2RAT persistence flow, launching mshta to fetch scripts and register Run-key persistence. The CHM samples contact infrastructure such as shacc.kr and 141.105.65.165 to receive commands and return Base64-encoded results, while a separate LNK variant drops a password text file and VBS script that retrieves additional code from hondes.getenjoyment.net. The report highlights continued abuse of CHM and LNK lures to make victims open malicious helper files alongside benign documents.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://hondes.getenjoyment.net/… 2023-03-10 2024-09-05
DOMAIN hondes.getenjoyment.net 2023-03-10 2024-09-05
HASH 809528921de39530de59e3793d74af98 2023-03-10 2023-03-21
URL http://shacc.kr/skin/product/1.… 2023-03-03 2023-03-21
DOMAIN shacc.kr 2023-03-03 2023-03-21
IPv4 141.105.65.165 2023-03-10 2023-03-16
HASH 2b79e2bd6548118c942480a52b5a1669 2023-03-10 2023-03-10
HASH b39182a535f41699280ca088eef0f258 2023-03-10 2023-03-10

Related Actors

Related Reports

« Back