프로필 양식 위장한 한글문서 (OLE개체)
2022-08-29 • Ahnlab • Hangul document disguised as profile form (OLE object) •
A malicious Hangul document disguised as a profile or personal-information form used embedded OLE objects and hidden hyperlinks to launch copied Windows binaries from the Temp directory. Clicking form fields executed a local LNK that ran a renamed mshta binary against hxxp://yukkimmo.sportsontheweb[.]net/hw.php, enabling attacker-controlled commands. Additional observed commands used a renamed PowerShell binary to download and execute script content from hxxp://yukkimmo.sportsontheweb[.]net/h.txt. The script downloaded PE data, hollowed System32\cmd.exe, tracked recent HWP link filenames, and replaced the opened document with another HWP that could contain a Flash object exploiting CVE-2018-15982. The report matters because it shows reuse of an older HWP Flash exploit chain with OLE, LNK, mshta, PowerShell, and document-replacement techniques that can support further attacker commands.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 65993d1cb0d1d7ce218fb267ee36f7c1 | 2022-08-29 | 2022-08-29 |
| HASH | 330f2f1eb6dc3d753b756a27694ef89b | 2022-08-29 | 2022-08-29 |
| HASH | 2f4ed70149da3825be16b6057bf7b8df | 2022-08-29 | 2022-08-29 |
| HASH | 804d12b116bb40282fbf245db885c093 | 2022-08-29 | 2022-08-29 |
| HASH | caa923803152dd9e6b5bf7f6b816ae98 | 2022-08-29 | 2022-08-29 |
| HASH | 9a13173df687549cfce3b36d8a4e20d3 | 2022-08-29 | 2022-08-29 |
| HASH | 76f8ccf8313af617df28e8e1f7f39f73 | 2022-08-29 | 2022-08-29 |
| URL | http://yukkimmo.sportsontheweb.… | 2022-08-29 | 2022-08-29 |
| URL | http://yukkimmo.sportsontheweb.… | 2022-08-29 | 2022-08-29 |
| URL | http://yukkimmo.sportsontheweb.… | 2022-08-29 | 2022-08-29 |
| DOMAIN | yukkimmo.sportsontheweb.net | 2022-08-29 | 2022-08-29 |
| URL | http://www.sjem.co.kr/admin/dat… | 2020-11-25 | 2022-08-29 |