한컴오피스 한글악성코드 분석보고서

2015-09-01 Somansa Hancom Office Hangul Malware Analysis Report

https://www.somansa.com/wp-content/uploads/2017/02/201509SecurityReport.pdf

Attachments

201509SecurityReport.pdf (1 MB)

Thumbnail for 한컴오피스 한글악성코드 분석보고서

Somansa analyzes malicious HWP documents attributed in the report to Kimsuky and aimed at specific South Korean institutions through a Hangul Office vulnerability that had already been patched. The documents use heap spraying and shellcode to extract encrypted embedded payloads, inject code into notepad.exe, and load a dropped DLL named ~tmp.dll or ~tmp.dlll. The DLL attempts process-staged execution through explorer.exe and svchost.exe, uses a sysprep.exe and cryptbase.dll UAC bypass path, registers a TelnetManagement service, and copies itself as telnet.dll or websec.dll for persistence. The malware tries to weaken local security controls by modifying V3, Windows Security Center, and firewall-related registry values, then collects host information and communicates through attacker-controlled mail.bg or Hotmail accounts to exfiltrate data and receive additional payloads.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d588c784dd82b74e4f63df2453e41ad… 2015-09-01 2015-09-01
HASH eb46650f15a8f3ddf287946ccbea8cf… 2015-09-01 2015-09-01
HASH 1a9e433e9e7ce6858ef1c6e08a696c9… 2015-09-01 2015-09-01
HASH 71abdc099d4cc2848e1eb3dda7f798a… 2015-09-01 2015-09-01

Related Actors

Related Reports

« Back