HWP + SlackBot Malware Analysis
2019-11-12 • lysine7 •
The analysis examines two suspicious HWP samples found on VirusTotal that used different filenames but shared the same embedded PostScript component. One lure posed as a new coin listing application and created an executable in the Windows Startup folder from encoded script data. The author notes similarities to known attack patterns that use PostScript in HWP documents to stage payloads for persistence and execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 95fe089b63c095bfb2b25e8c6914d19d | 2019-11-12 | 2019-11-12 |
| HASH | d6709d7dad54e31d87a2c721f09714fb | 2019-11-12 | 2019-11-12 |