‘BIO 양식’ 제목의 워드문서 유포 중

2021-08-03 Ahnlab A word document titled ‘BIO Form' is being distributed.

https://asec.ahnlab.com/ko/25861/

Thumbnail for ‘BIO 양식’ 제목의 워드문서 유포 중

AhnLab describes continued distribution of malicious Word documents using a “BIO form” lure, likely aimed at professors or research-center heads involved in North Korea-related topics. The DOCX file uses an external link to fetch a malicious BIO.dotm template containing obfuscated macros. Instead of directly downloading from a URL as in earlier variants, the macro writes a PowerShell command into C:\windows\temp\Ahnlab.log and then executes it to retrieve a script from zenma.getenjoyment.net. The report connects the technique to earlier targeted APT attempts using external Word templates and advises users to remain cautious with personalized biography-form documents.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://jupit.getenjoyment.net/P… 2021-08-03 2021-08-03
URL http://zenma.getenjoyment.net/j… 2021-08-03 2021-08-03
DOMAIN zenma.getenjoyment.net 2021-08-03 2021-08-03
DOMAIN jupit.getenjoyment.net 2021-07-15 2021-08-03

Related Reports

« Back