HWP Malware.. Please Give me back my weekend.......
2018-11-24 • kino •
A malicious HWP document themed as a National Security Council Policy Advisory Committee plenary meeting plan was found after likely use in attacks, with metadata showing author and last-saved values of yoonjh337 and cha0520. The document contains an embedded EPS file with exploit code and shellcode that decrypts additional code, launches iexplorer.exe in suspended mode, and injects the next-stage shellcode. The injected shellcode decrypts embedded data and attempts to download and run another file, although the source notes the download was no longer active at analysis time. The report provides hashes for the HWP sample and identifies hxxp://padosori[.]co[.]kr/_controller/admin/upload_sec/down[.]php as C2-related infrastructure for defender validation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 281160972ef8f657139d3801139e6783 | 2018-11-24 | 2019-07-03 |
| HASH | d29c6116691f6124e7c5b6b1ed05589… | 2018-11-24 | 2018-11-24 |
| HASH | 0a7f9204e62041f86464e44c8ab902c… | 2018-11-24 | 2018-11-24 |
| URL | http://padosori.co.kr/_controll… | 2018-11-24 | 2018-11-24 |
| DOMAIN | padosori.co.kr | 2018-11-24 | 2018-11-24 |