포스트스크립트를 이용한 HWP 한글 문서 악성코드 주의
2020-04-28 • Ahnlab • Beware of malware in HWP Hangul documents using PostScript •
ASEC warned that HWP malware using Encapsulated PostScript objects had increased in April 2020, including lures impersonating COVID-19 infection-control organizations and Korea Hydro & Nuclear Power recruitment notices. The attacker inserted malicious EPS content into otherwise normal-looking Hangul documents and simplified the PostScript syntax so that CVE-2017-8291 exploitation and shellcode execution were hidden inside hexadecimal data executed with cvx and exec. The payloads downloaded files from external servers, saved them under image-like names such as skype.jpg or photo.jpg, and executed them with regsvr32 or saved another download as svchost.exe for execution. The report emphasizes that the simplified PostScript pattern made detection harder and required behavioral and exploit-focused detection rather than relying only on visible document content.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f90770d4a320bf15e51fdd770845dce5 | 2020-04-28 | 2020-04-28 |
| HASH | cbedf01fa62a94219e70dae13d3dc984 | 2020-04-28 | 2020-04-28 |
| URL | http://matteoragazzini.it/wp-co… | 2020-04-28 | 2020-04-28 |
| URL | https://matteoragazzini.it/wp-c… | 2020-04-28 | 2020-04-28 |
| DOMAIN | matteoragazzini.it | 2020-04-28 | 2020-04-28 |
| HASH | 4662dfa19bd590b1088befa28426a161 | 2020-04-15 | 2020-04-28 |
| URL | http://teslacontrols.ir/wp-incl… | 2020-04-15 | 2020-04-28 |
| URL | http://teslacontrols.ir/wp-incl… | 2020-04-15 | 2020-04-28 |
| DOMAIN | teslacontrols.ir | 2020-04-15 | 2020-04-28 |