How To: Analyzing a Malicious Hangul Word Processor Document from a DPRK Threat Actor Group

2019-02-25 Norfolk

https://norfolkinfosec.com/how-to-analyzing-a-malicious-hangul-word-processor-document-from-a-dprk-threat-actor-group/

Thumbnail for How To: Analyzing a Malicious Hangul Word Processor Document from a DPRK Threat Actor Group

Norfolk Infosec walks through analysis of a malicious Hangul Word Processor document associated with DPRK-linked activity and prior ESTsecurity reporting. The sample includes published MD5, SHA1, and SHA256 values and, when opened, spawns Internet Explorer while making a network request to a compromised Korean website. The analysis focuses on the HWP BIN0003.eps stream: the zlib-compressed EPS content is decompressed, modified to print a second layer, and yields shellcode beginning with a NOP sled for further emulation and debugging. The report is useful for defenders because it documents practical HWP/EPS exploit-analysis steps for malware aimed at Hangul Office environments without asserting a named vendor cluster beyond the source wording.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7a86e6bffba91997553ac4cf0baec40… 2019-02-25 2019-02-25
HASH 5d9e5c7b1b71af3c5f058f8521d383d… 2019-02-25 2019-02-25
HASH f2e936ff1977d123809d167a2a51cdeb 2019-02-25 2019-02-25
« Back