포스트스크립트를 이용한 HWP 한글 문서 악성코드 주의

2020-04-28 Ahnlab Beware of malware in HWP Hangul documents using PostScript

https://asec.ahnlab.com/1315

Thumbnail for 포스트스크립트를 이용한 HWP 한글 문서 악성코드 주의

ASEC warned that HWP malware using Encapsulated PostScript objects had increased in April 2020, including lures impersonating COVID-19 infection-control organizations and Korea Hydro & Nuclear Power recruitment notices. The attacker inserted malicious EPS content into otherwise normal-looking Hangul documents and simplified the PostScript syntax so that CVE-2017-8291 exploitation and shellcode execution were hidden inside hexadecimal data executed with cvx and exec. The payloads downloaded files from external servers, saved them under image-like names such as skype.jpg or photo.jpg, and executed them with regsvr32 or saved another download as svchost.exe for execution. The report emphasizes that the simplified PostScript pattern made detection harder and required behavioral and exploit-focused detection rather than relying only on visible document content.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f90770d4a320bf15e51fdd770845dce5 2020-04-28 2020-04-28
HASH cbedf01fa62a94219e70dae13d3dc984 2020-04-28 2020-04-28
URL http://matteoragazzini.it/wp-co… 2020-04-28 2020-04-28
URL https://matteoragazzini.it/wp-c… 2020-04-28 2020-04-28
DOMAIN matteoragazzini.it 2020-04-28 2020-04-28
HASH 4662dfa19bd590b1088befa28426a161 2020-04-15 2020-04-28
URL http://teslacontrols.ir/wp-incl… 2020-04-15 2020-04-28
URL http://teslacontrols.ir/wp-incl… 2020-04-15 2020-04-28
DOMAIN teslacontrols.ir 2020-04-15 2020-04-28

Related Reports

« Back