"프로필 양식" 워드 문서를 활용한 APT 공격
2022-05-02 • Secu I • APT attack using "profile form" word document •
SECUI STIC observed a North Korea-backed APT campaign targeting South Korean security and unification-related organizations with spearphishing emails carrying a password-protected Word document named as a profile form. When the victim enabled macros, the document ran Document_Open VBA code that launched PowerShell, contacted the C2 server, and downloaded an additional PowerShell script. The script collected file listings from Program Files paths and systeminfo output, saved the data under %APPDATA%\Ahnlab\Ahnlab.hwp, and could receive further commands for background execution. Communications with uekaf.myartsonline[.]com used XOR processing with a 160-byte key to obscure collected data and attacker commands, with related URLs and hashes provided as IOCs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9a54b0adff7424a02edfe7c365b6a69… | 2022-05-02 | 2022-05-02 |
| HASH | 7a9d43c263347243fd67cc59ee8e719… | 2022-05-02 | 2022-05-02 |
| URL | http://uekaf.myartsonline.com/h… | 2022-05-02 | 2022-05-02 |
| URL | http://uekaf.myartsonline.com/h… | 2022-05-02 | 2022-05-02 |
| URL | http://uekaf.myartsonline.com/h… | 2022-05-02 | 2022-05-02 |
| URL | http://uekaf.myartsonline.com/h… | 2022-05-02 | 2022-05-02 |
| DOMAIN | uekaf.myartsonline.com | 2022-05-02 | 2022-05-02 |