HWP + SlackBot Malware Analysis

2019-11-12 lysine7

https://lysine7.tistory.com/66

Thumbnail for HWP + SlackBot Malware Analysis

The analysis examines two suspicious HWP samples found on VirusTotal that used different filenames but shared the same embedded PostScript component. One lure posed as a new coin listing application and created an executable in the Windows Startup folder from encoded script data. The author notes similarities to known attack patterns that use PostScript in HWP documents to stage payloads for persistence and execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 95fe089b63c095bfb2b25e8c6914d19d 2019-11-12 2019-11-12
HASH d6709d7dad54e31d87a2c721f09714fb 2019-11-12 2019-11-12
« Back