Korean MalDoc Drops Evil New Years Presents

2017-02-23 Cisco Talos

http://blog.talosintelligence.com/2017/02/korean-maldoc.html

Thumbnail for Korean MalDoc Drops Evil New Years Presents

Talos analyzes a Korean HWP malicious document themed around analysis of North Korea's 2017 New Year address and apparently impersonating South Korea's Ministry of Unification. The document embedded OLE objects that dropped PE files when users clicked linked decoy documents, then executed wscript.exe, injected shellcode, unpacked a second-stage PE, and collected host details such as execution path, BIOS model, and a generated system ID. The loader contacted compromised Korean government or other websites, including kgls.or.kr, to post reconnaissance data and retrieve a final payload masquerading as a JPG file, though the final payload was unavailable during analysis. Talos assesses the activity as a targeted attack against South Korean public-sector users by a sophisticated actor using native Korean-language lures, short-lived infrastructure, and a regional file format that many defenses may not inspect well.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7ebc9a1fd93525fc42277efbccecf5a… 2017-02-23 2018-02-27
HASH 7d8008028488edd26e665a3d4f70576… 2017-02-23 2018-02-27
HASH 6c372f29615ce8ae2cdf257e9f26178… 2017-02-23 2018-02-27
HASH 95192de1f3239d5c0a7075627cf9845… 2017-02-23 2018-02-27
HASH 19e4c45c0cd992564532b89a4dc1f35… 2017-02-23 2018-02-27
HASH 3d442c4457cf921b7a335c0d7276bea… 2017-02-23 2018-01-16
HASH 281828d6f5bd377f91c6283c34896d0… 2017-02-23 2018-01-16
HASH 761454dafba7e191587735c0dc5c6c8… 2017-02-23 2018-01-16
HASH 3a0fc4cc145eafe20129e9c53aac424… 2017-02-23 2018-01-16
HASH 7e810cb159fab5baccee7e72708d974… 2017-02-23 2018-01-16
HASH f080f019073654acbe6b7ab735d3fd2… 2017-02-23 2018-01-16
HASH 21b098d721ea88bf237c08cdb5c619a… 2017-02-23 2018-01-16
HASH 930fce7272ede29833abbfb5df4e32e… 2017-02-23 2018-01-16
HASH 4b20883386665bd205ac50f34f7b629… 2017-02-23 2018-01-16

Related Reports

« Back