"프로필 양식" 워드 문서를 활용한 APT 공격

2022-05-02 Secu I APT attack using "profile form" word document

https://stic.secui.com/main/main/threatInfo?id=1

SECUI STIC observed a North Korea-backed APT campaign targeting South Korean security and unification-related organizations with spearphishing emails carrying a password-protected Word document named as a profile form. When the victim enabled macros, the document ran Document_Open VBA code that launched PowerShell, contacted the C2 server, and downloaded an additional PowerShell script. The script collected file listings from Program Files paths and systeminfo output, saved the data under %APPDATA%\Ahnlab\Ahnlab.hwp, and could receive further commands for background execution. Communications with uekaf.myartsonline[.]com used XOR processing with a 160-byte key to obscure collected data and attacker commands, with related URLs and hashes provided as IOCs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9a54b0adff7424a02edfe7c365b6a69… 2022-05-02 2022-05-02
HASH 7a9d43c263347243fd67cc59ee8e719… 2022-05-02 2022-05-02
URL http://uekaf.myartsonline.com/h… 2022-05-02 2022-05-02
URL http://uekaf.myartsonline.com/h… 2022-05-02 2022-05-02
URL http://uekaf.myartsonline.com/h… 2022-05-02 2022-05-02
URL http://uekaf.myartsonline.com/h… 2022-05-02 2022-05-02
DOMAIN uekaf.myartsonline.com 2022-05-02 2022-05-02
« Back