Distribution of Malware Disguised as Coin and Investment-related Content
2023-08-09 • Ahnlab •
ASEC reports coin exchange and investment-themed malware distributed as SFX executables disguised with Word/PDF icons and as a macro-enabled Word document. The SFX samples opened decoy documents while using mshta.exe to run scripts from partner24.kr paths, and the Word variant copied wscript.exe as word.exe, downloaded a Base64-encoded script from the same infrastructure, and executed it as set.sl. ASEC suspected Kimsuky involvement based on the unusual “Chnome” User-Agent in the macro and shared coin-themed filenames/C2 infrastructure across the samples. Although the final C2 script was unavailable during analysis, the chain could support credential theft, additional malware download, and other operator-directed actions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b6614471ebf288689d33808c376540e1 | 2023-07-31 | 2023-08-09 |
| HASH | 8a5fd1e9c9841ff0253b2a6f1e533d0e | 2023-07-31 | 2023-08-09 |
| HASH | 17daf3ea7b80ee95792d4b3332a3390d | 2023-07-31 | 2023-08-09 |
| HASH | 002105e21f1bddf68e59743c440e416a | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |