한국국가정보학회 학회장 선거공고 내용의 악성 HWP 유포
2019-11-18 • Ahnlab • Distribution of malicious HWP containing the contents of the election announcement for the President of the Korean Society for National Informatics •
AhnLab analyzed a malicious HWP document disguised as an election notice and candidate application for the Korean Society for National Informatics chair. The document placed an embedded EPS object on the first page; after execution, a VBS startup entry invoked PowerShell with Base64-encoded data to download and run an external file. The report identifies the suspected filename, MD5 and SHA-256 sample hashes, startup-path artifacts, and AhnLab detections including VBS/Downloader, BinImage/Agent, and HWP/Dropper, giving defenders concrete HWP/EPS exploit and downloader indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 72fd996d651baaad444ac7664b39f66… | 2019-11-18 | 2019-11-18 |
| HASH | e232ee98e0777fe589f600aa6e62d967 | 2019-11-18 | 2019-11-18 |