CVE-2021-40444 취약점을 이용한 대북 관련 악성 문서

2021-11-17 Ahnlab Malicious documents related to North Korea using the vulnerability of CVE-2021-40444

https://asec.ahnlab.com/ko/28690/

Thumbnail for CVE-2021-40444 취약점을 이용한 대북 관련 악성 문서

AhnLab ASEC reports malicious Office documents using CVE-2021-40444 with North Korea-related lure filenames, showing attackers quickly adopting the MSHTML remote-code-execution vulnerability after its disclosure. The documents used external links and the MHTML protocol to reach a malicious URL, execute JavaScript through the Office/Internet Explorer rendering engine, download a CAB archive, and load a malicious INF-based DLL. The lure content referenced a reunification-related seminar scheduled for November 18, making the documents appear relevant to users interested in North Korea policy issues. AhnLab observed both documents contacting the same infrastructure and published representative hashes plus a defanged officeversion.mywebcommunity.org URL for detection and follow-up.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 809c4c40537c60e224363b94296fbbf2 2021-11-17 2021-11-17
HASH 1132d2a12b6fd6cbbc8046df3612d725 2021-11-17 2021-11-17
HASH 2edbab4834a1315b476278fb6ed2592f 2021-11-17 2021-11-17
URL http://officeversion.mywebcommu… 2021-11-17 2021-11-17
DOMAIN officeversion.mywebcommunity.org 2021-11-11 2021-11-17

Related Reports

« Back