한컴오피스 한글악성코드 분석보고서
2015-09-01 • Somansa • Hancom Office Hangul Malware Analysis Report •
https://www.somansa.com/wp-content/uploads/2017/02/201509SecurityReport.pdf
Attachments
201509SecurityReport.pdf (1 MB)
Somansa analyzes malicious HWP documents attributed in the report to Kimsuky and aimed at specific South Korean institutions through a Hangul Office vulnerability that had already been patched. The documents use heap spraying and shellcode to extract encrypted embedded payloads, inject code into notepad.exe, and load a dropped DLL named ~tmp.dll or ~tmp.dlll. The DLL attempts process-staged execution through explorer.exe and svchost.exe, uses a sysprep.exe and cryptbase.dll UAC bypass path, registers a TelnetManagement service, and copies itself as telnet.dll or websec.dll for persistence. The malware tries to weaken local security controls by modifying V3, Windows Security Center, and firewall-related registry values, then collects host information and communicates through attacker-controlled mail.bg or Hotmail accounts to exfiltrate data and receive additional payloads.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d588c784dd82b74e4f63df2453e41ad… | 2015-09-01 | 2015-09-01 |
| HASH | eb46650f15a8f3ddf287946ccbea8cf… | 2015-09-01 | 2015-09-01 |
| HASH | 1a9e433e9e7ce6858ef1c6e08a696c9… | 2015-09-01 | 2015-09-01 |
| HASH | 71abdc099d4cc2848e1eb3dda7f798a… | 2015-09-01 | 2015-09-01 |