‘2021년 국방부 업무보고 수정’ 문서로 위장한 악성코드 유포

2021-02-03 Ahnlab Spreading malicious code disguised as ‘2021 Ministry of Defense Business Report Revision' document

https://asec.ahnlab.com/ko/20057

Thumbnail for ‘2021년 국방부 업무보고 수정’ 문서로 위장한 악성코드 유포

ASEC observed malware distributed as a PIF executable disguised as a revised 2021 Ministry of National Defense work-report document. When run, the file displayed a legitimate PDF copied from the ministry website while silently dropping a malicious DLL at C:\ProgramData\Intel\Driver\driver.cfg. The DLL was executed with regsvr32.exe and persisted through a scheduled task named Disk0 that ran every 30 minutes. The sample was compiled on January 23, 2021 and was expected to contact attacker-controlled C2 infrastructure at exchange.amikbvx.cf and imap.pamik.cf for further commands, with two hashes and AhnLab detections provided for tracking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7e041b101e1e574fb81f3f0cdf1c72b8 2021-02-03 2021-06-23
HASH 447163d776b62bf0b1c652c996cc0586 2021-02-03 2021-02-03
URL http://exchange.amikbvx.cf/ 2021-02-03 2021-02-03
URL http://imap.pamik.cf/ 2021-02-03 2021-02-03
DOMAIN imap.pamik.cf 2021-02-03 2021-02-03
DOMAIN exchange.amikbvx.cf 2021-02-03 2021-02-03

Related Reports

« Back