프로필 양식 위장한 한글문서 (OLE개체)

2022-08-29 Ahnlab Hangul document disguised as profile form (OLE object)

https://asec.ahnlab.com/ko/38216/

Thumbnail for 프로필 양식 위장한 한글문서 (OLE개체)

A malicious Hangul document disguised as a profile or personal-information form used embedded OLE objects and hidden hyperlinks to launch copied Windows binaries from the Temp directory. Clicking form fields executed a local LNK that ran a renamed mshta binary against hxxp://yukkimmo.sportsontheweb[.]net/hw.php, enabling attacker-controlled commands. Additional observed commands used a renamed PowerShell binary to download and execute script content from hxxp://yukkimmo.sportsontheweb[.]net/h.txt. The script downloaded PE data, hollowed System32\cmd.exe, tracked recent HWP link filenames, and replaced the opened document with another HWP that could contain a Flash object exploiting CVE-2018-15982. The report matters because it shows reuse of an older HWP Flash exploit chain with OLE, LNK, mshta, PowerShell, and document-replacement techniques that can support further attacker commands.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 65993d1cb0d1d7ce218fb267ee36f7c1 2022-08-29 2022-08-29
HASH 330f2f1eb6dc3d753b756a27694ef89b 2022-08-29 2022-08-29
HASH 2f4ed70149da3825be16b6057bf7b8df 2022-08-29 2022-08-29
HASH 804d12b116bb40282fbf245db885c093 2022-08-29 2022-08-29
HASH caa923803152dd9e6b5bf7f6b816ae98 2022-08-29 2022-08-29
HASH 9a13173df687549cfce3b36d8a4e20d3 2022-08-29 2022-08-29
HASH 76f8ccf8313af617df28e8e1f7f39f73 2022-08-29 2022-08-29
URL http://yukkimmo.sportsontheweb.… 2022-08-29 2022-08-29
URL http://yukkimmo.sportsontheweb.… 2022-08-29 2022-08-29
URL http://yukkimmo.sportsontheweb.… 2022-08-29 2022-08-29
DOMAIN yukkimmo.sportsontheweb.net 2022-08-29 2022-08-29
URL http://www.sjem.co.kr/admin/dat… 2020-11-25 2022-08-29

Related Reports

« Back