Distribution of Malware Disguised as Coin and Investment-related Content

2023-08-09 Ahnlab

https://asec.ahnlab.com/en/55944/

Thumbnail for Distribution of Malware Disguised as Coin and Investment-related Content

ASEC reports coin exchange and investment-themed malware distributed as SFX executables disguised with Word/PDF icons and as a macro-enabled Word document. The SFX samples opened decoy documents while using mshta.exe to run scripts from partner24.kr paths, and the Word variant copied wscript.exe as word.exe, downloaded a Base64-encoded script from the same infrastructure, and executed it as set.sl. ASEC suspected Kimsuky involvement based on the unusual “Chnome” User-Agent in the macro and shared coin-themed filenames/C2 infrastructure across the samples. Although the final C2 script was unavailable during analysis, the chain could support credential theft, additional malware download, and other operator-directed actions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b6614471ebf288689d33808c376540e1 2023-07-31 2023-08-09
HASH 8a5fd1e9c9841ff0253b2a6f1e533d0e 2023-07-31 2023-08-09
HASH 17daf3ea7b80ee95792d4b3332a3390d 2023-07-31 2023-08-09
HASH 002105e21f1bddf68e59743c440e416a 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09

Related Actors

Related Reports

« Back