한글문서(HWP) 내부 플래쉬 취약점 이용한 새로운 공격

2020-11-25 Ahnlab New attack using Hangul Document (HWP) internal flash vulnerability

https://asec.ahnlab.com/ko/16383/

Thumbnail for 한글문서(HWP) 내부 플래쉬 취약점 이용한 새로운 공격

ASEC observed an HWP attack that embedded a Flash vulnerability object for CVE-2018-15982, using a lure titled Unification Korea Forum participant honorarium profile form. The document was believed to download and run a Flash file from sjem.co.kr inside the HWP.EXE process, a likely evasion choice because exploitation occurred outside the browser. Shellcode launched cmd.exe, injected additional code, and attempted to download a binary from OneDrive; AhnLab telemetry later identified a HncUpdate.exe payload with information-stealing and remote-command functions. The malware collected user and file information, uploaded data to Korean-hosted infrastructure, and referenced Chinotto-related paths, mutex values and C2 URLs in its internal strings.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://www.sjem.co.kr/admin/dat… 2020-11-25 2022-08-29
DOMAIN haeundaejugong.com 2020-11-25 2021-11-29
URL https://onedrive.live.com/downl… 2020-11-25 2020-11-25

Related Reports

« Back