HWP Malware.. Please Give me back my weekend.......

2018-11-24 kino

http://sfkino.tistory.com/m/72

Thumbnail for HWP Malware.. Please Give me back my weekend.......

A malicious HWP document themed as a National Security Council Policy Advisory Committee plenary meeting plan was found after likely use in attacks, with metadata showing author and last-saved values of yoonjh337 and cha0520. The document contains an embedded EPS file with exploit code and shellcode that decrypts additional code, launches iexplorer.exe in suspended mode, and injects the next-stage shellcode. The injected shellcode decrypts embedded data and attempts to download and run another file, although the source notes the download was no longer active at analysis time. The report provides hashes for the HWP sample and identifies hxxp://padosori[.]co[.]kr/_controller/admin/upload_sec/down[.]php as C2-related infrastructure for defender validation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 281160972ef8f657139d3801139e6783 2018-11-24 2019-07-03
HASH d29c6116691f6124e7c5b6b1ed05589… 2018-11-24 2018-11-24
HASH 0a7f9204e62041f86464e44c8ab902c… 2018-11-24 2018-11-24
URL http://padosori.co.kr/_controll… 2018-11-24 2018-11-24
DOMAIN padosori.co.kr 2018-11-24 2018-11-24

Related Reports

« Back