한국국가정보학회 학회장 선거공고 내용의 악성 HWP 유포

2019-11-18 Ahnlab Distribution of malicious HWP containing the contents of the election announcement for the President of the Korean Society for National Informatics

https://asec.ahnlab.com/1267

Thumbnail for 한국국가정보학회 학회장 선거공고 내용의 악성 HWP 유포

AhnLab analyzed a malicious HWP document disguised as an election notice and candidate application for the Korean Society for National Informatics chair. The document placed an embedded EPS object on the first page; after execution, a VBS startup entry invoked PowerShell with Base64-encoded data to download and run an external file. The report identifies the suspected filename, MD5 and SHA-256 sample hashes, startup-path artifacts, and AhnLab detections including VBS/Downloader, BinImage/Agent, and HWP/Dropper, giving defenders concrete HWP/EPS exploit and downloader indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 72fd996d651baaad444ac7664b39f66… 2019-11-18 2019-11-18
HASH e232ee98e0777fe589f600aa6e62d967 2019-11-18 2019-11-18

Related Reports

« Back