한컴 오피스 문서파일로 위장하여 유포중인 악성코드 증적 추적(RedEyes)

2023-05-25 Ahnlab Tracking traces of malicious code being distributed disguised as Hancom Office document files (RedEyes)

https://asec.ahnlab.com/ko/53273/

Thumbnail for 한컴 오피스 문서파일로 위장하여 유포중인 악성코드 증적 추적(RedEyes)

AhnLab observed malware distributed as an executable disguised with a Hancom Office document icon and named like a Korean-language column file, linking the activity to RedEyes/APT37 infrastructure. When executed, the malware copies itself under AppData as onedrivenew.exe, drops and opens a decoy Hancom document, injects into the legitimate mstsc.exe process, and deletes the original file through cmd. It establishes persistence with a Run-key entry named onedrivenew and schedules OneDriveOp to invoke mshta.exe every 60 minutes against a URL on a compromised legitimate website. AhnLab notes that the inserted web shell matches prior RedEyes/APT37 targeting of website-production firms and provides representative indicators including the MD5 93fc0fb9b87a00b38f18c1cc4ee02e50 and ingarchi.com URLs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 93fc0fb9b87a00b38f18c1cc4ee02e50 2023-05-25 2023-06-01
URL http://ingarchi.com/bbs/data/cu… 2023-05-25 2023-06-01
URL http://ingarchi.com/bbs/data/cu… 2023-05-25 2023-06-01
DOMAIN ingarchi.com 2023-05-25 2023-06-01

Related Actors

Related Reports

« Back