‘2021년 국방부 업무보고 수정’ 문서로 위장한 악성코드 유포
2021-02-03 • Ahnlab • Spreading malicious code disguised as ‘2021 Ministry of Defense Business Report Revision' document •
ASEC observed malware distributed as a PIF executable disguised as a revised 2021 Ministry of National Defense work-report document. When run, the file displayed a legitimate PDF copied from the ministry website while silently dropping a malicious DLL at C:\ProgramData\Intel\Driver\driver.cfg. The DLL was executed with regsvr32.exe and persisted through a scheduled task named Disk0 that ran every 30 minutes. The sample was compiled on January 23, 2021 and was expected to contact attacker-controlled C2 infrastructure at exchange.amikbvx.cf and imap.pamik.cf for further commands, with two hashes and AhnLab detections provided for tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7e041b101e1e574fb81f3f0cdf1c72b8 | 2021-02-03 | 2021-06-23 |
| HASH | 447163d776b62bf0b1c652c996cc0586 | 2021-02-03 | 2021-02-03 |
| URL | http://exchange.amikbvx.cf/ | 2021-02-03 | 2021-02-03 |
| URL | http://imap.pamik.cf/ | 2021-02-03 | 2021-02-03 |
| DOMAIN | imap.pamik.cf | 2021-02-03 | 2021-02-03 |
| DOMAIN | exchange.amikbvx.cf | 2021-02-03 | 2021-02-03 |