한글 파일에 숨어든 '고스트'

2019-07-03 Ahnlab ‘Ghost' hiding in Hangul files

https://k.kakaocdn.net/dn/cZgWbQ/btqwtmlyQnI/vDG9Ob080r38Zg5n9Iase0/AhnLab_ASEC_%ED%95%9C%EA%B8%80%ED%8C%8C%EC%9D%BC%EC%97%90%EC%88%A8%EC%96%B4%EB%93%A0%27%EA%B3%A0%EC%8A%A4%ED%8A%B8%27.pdf?attach=1&knm=tfile.pdf

Attachments

AhnLab_ASEC_ED959CEAB880ED8C8CEC9DBCEC9790EC88A8EC96B4EB93A027EAB3_UkCTFx6.pdf (5 MB)

AhnLab analyzed a long-running wave of malicious HWP files that abused the Ghostscript CVE-2017-8291 “GhostButt” vulnerability embedded in EPS content. The report explains that HWP attacks against Korean users have often been targeted, with decoys crafted for public agencies, government-related themes, cryptocurrency businesses, companies, and job seekers. In affected HWP versions, embedded EPS files were decompressed into temporary files and passed by Hwp.exe to Ghostscript components such as gbb.exe and gswin32c.exe, where malicious PostScript could trigger the vulnerability. The exploit relies on a type-confusion condition in Ghostscript’s PostScript processing, allowing attackers to alter execution flow while making variants through scripting, encoding, and variable changes. The report matters for defenders because the same vulnerability was reused for roughly two years, showing why legacy HWP/EPS handling and Ghostscript behavior remain important telemetry points.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c87696a3224f97e30200a93021e44ab6 2019-07-03 2019-11-18
HASH 48d9e625ea3efbcbef3963c8714544a7 2019-02-07 2019-11-18
HASH f392492ef5ea1b399b4c0af38810b0d6 2018-09-13 2019-11-18
HASH ff9eff561fd793ddb9011cf7006d5f6c 2019-07-03 2019-08-24
HASH d4a8acca0c0af629f600234d230ab0cf 2019-07-03 2019-07-03
HASH 6d980c4ec6ca4561c354f417960154c5 2019-07-03 2019-07-03
HASH ec7ba18cc775a58647943e16d51d01ac 2019-07-03 2019-07-03
HASH eb4e82da565d70cfe0951adc12608148 2019-07-03 2019-07-03
HASH b84e781bbff0bbff63f3d88c6ce4d84e 2019-07-03 2019-07-03
HASH ec06c31cb0992bb378a185f1e781563b 2019-07-03 2019-07-03
HASH ce3350131bbfca1a330dad62653a132d 2019-07-03 2019-07-03
HASH 13570dcee3d217ff90f1ea912daec8fc 2019-07-03 2019-07-03
HASH 2cd28ee74910be7a023d10e3860eae5c 2019-07-03 2019-07-03
HASH 398150acc728dfa7a67cb07584045825 2019-07-03 2019-07-03
HASH 7de8b065e2587765fca5a163f958637d 2019-07-03 2019-07-03
HASH 3d0d71fdedfd8945d78b64cdf0fb11ed 2019-07-03 2019-07-03
HASH a36cc933b1c5902d98a3db3143f4b419 2019-07-03 2019-07-03
HASH a6dd0124fb5cb054f1614f13f3f2fe48 2019-07-03 2019-07-03
HASH 3d4b6b947283e70cf94a8e1112edfd72 2019-07-03 2019-07-03
HASH e9ea50d43c5f1e9874895dd352a505a7 2019-07-03 2019-07-03
HASH df7328f9f6fbab00c63e6c398c961502 2019-07-03 2019-07-03
HASH 8152e241b3f1fdb85d21bfcf2aa8ab1d 2019-07-03 2019-07-03
HASH e50256b8e8496a030561f5ad6d9bda1e 2019-07-03 2019-07-03
HASH b39228c9538fd79dc425964dde1501d9 2019-07-03 2019-07-03
HASH da02193fc7f2a628770382d9b39fe8e0 2019-07-03 2019-07-03
HASH 87c748f59f97dfb29b48079532b39e5c 2019-07-03 2019-07-03
HASH 9ca962eb74bbdb238609e192e1a33a40 2019-07-03 2019-07-03
HASH abafa0cbfbe18afe6dd635d14e7d03d3 2019-07-03 2019-07-03
HASH f5b5a3f9eab0219d4f91a1f61541c61e 2019-07-03 2019-07-03
HASH 85684409e402d1f518552e8e18f27a98 2019-07-03 2019-07-03
HASH 3667a4032215cbe4420eab911d4414a7 2019-07-03 2019-07-03
HASH 5a7718f70ace857d2f9c9e09ec5d54f1 2019-07-03 2019-07-03
HASH f420757270d0987148b950f2066bbbab 2019-07-03 2019-07-03
HASH e0a48954a6728d7ed285600af26bad87 2019-07-03 2019-07-03
HASH 87b01ad040f3c4e9ca323039f97063e4 2019-07-03 2019-07-03
HASH 2a52138403a403316f22225964c3b9ae 2019-07-03 2019-07-03
HASH 09689e9311fd25817f2b88ae8d791435 2019-07-03 2019-07-03
HASH a0748e19b043ffe9bdf04c5d2df26689 2019-07-03 2019-07-03
HASH 63069c9bcc4f8e16412ea1a25f3edf14 2019-07-03 2019-07-03
HASH 0765b1fe1f761e4b50a48d525c23b678 2019-07-03 2019-07-03
HASH 1c0ee8e91704ca11cb4b9825541e8f7a 2019-07-03 2019-07-03
HASH a7b3b2c6e23a15f6fe0a722ebaa4459c 2019-07-03 2019-07-03
HASH dc06928356c90ac5b3dc3239868b88c7 2019-07-03 2019-07-03
URL http://git.ghostscript.com/?p=g… 2019-07-03 2019-07-03
DOMAIN bugzilla.redhat.com 2019-07-03 2019-07-03
DOMAIN bugs.ghostscript.com 2019-07-03 2019-07-03
HASH 281160972ef8f657139d3801139e6783 2018-11-24 2019-07-03
HASH a43dfbfad77b5aa974cd475744ab8182 2018-06-22 2019-07-03
HASH 2228fea495bee51dc88c1a0ed953450a 2018-06-22 2019-07-03
HASH e8bf331858b173eac8bd2b2227821022 2018-06-22 2019-07-03
HASH 06cfc6cda57fb5b67ee3eb0400dd5b97 2018-06-22 2019-07-03
HASH 631f1c63ff87399e5e73c7d94d62532f 2018-06-22 2019-07-03

Related Reports

« Back