한국 핵무장 관련 전문가 온라인 좌담회로 위장한 악성메일 주의
2022-01-25 • Hauri • Beware of malicious emails disguised as online discussions with experts on Korea's nuclear armament •
https://www.hauri.co.kr/security/issue_view.html?intSeq=412&page=1&article_num=324
Hauri reports malicious emails targeting Korean users by posing as invitations to an expert online discussion about Korea's nuclear armament. The lure uses a password-protected document and instructs recipients to enable content, which runs malicious macro code that collects PC information and sends it to attacker infrastructure. The macro then downloads and executes a VBS file from a C2 endpoint, saving it as %AppData%\Desktop.ini. The report provides concrete infrastructure indicators including Yulsohnyonsei[.]medianewsonline[.]com and http://koreajjjjj[.]sportsontheweb[.]net/0119/k.php, making the activity useful for detecting document-based social engineering tied to Korean security-policy themes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | koreajjjjj.sportsontheweb.net | 2022-01-25 | 2022-08-25 |
| DOMAIN | yulsohnyonsei.medianewsonline.c… | 2022-01-25 | 2022-08-25 |
| URL | http://koreajjjjj.sportsonthewe… | 2022-01-25 | 2022-01-25 |