Korean MalDoc Drops Evil New Years Presents
2017-02-23 • Cisco Talos •
http://blog.talosintelligence.com/2017/02/korean-maldoc.html
Talos analyzes a Korean HWP malicious document themed around analysis of North Korea's 2017 New Year address and apparently impersonating South Korea's Ministry of Unification. The document embedded OLE objects that dropped PE files when users clicked linked decoy documents, then executed wscript.exe, injected shellcode, unpacked a second-stage PE, and collected host details such as execution path, BIOS model, and a generated system ID. The loader contacted compromised Korean government or other websites, including kgls.or.kr, to post reconnaissance data and retrieve a final payload masquerading as a JPG file, though the final payload was unavailable during analysis. Talos assesses the activity as a targeted attack against South Korean public-sector users by a sophisticated actor using native Korean-language lures, short-lived infrastructure, and a regional file format that many defenses may not inspect well.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7ebc9a1fd93525fc42277efbccecf5a… | 2017-02-23 | 2018-02-27 |
| HASH | 7d8008028488edd26e665a3d4f70576… | 2017-02-23 | 2018-02-27 |
| HASH | 6c372f29615ce8ae2cdf257e9f26178… | 2017-02-23 | 2018-02-27 |
| HASH | 95192de1f3239d5c0a7075627cf9845… | 2017-02-23 | 2018-02-27 |
| HASH | 19e4c45c0cd992564532b89a4dc1f35… | 2017-02-23 | 2018-02-27 |
| HASH | 3d442c4457cf921b7a335c0d7276bea… | 2017-02-23 | 2018-01-16 |
| HASH | 281828d6f5bd377f91c6283c34896d0… | 2017-02-23 | 2018-01-16 |
| HASH | 761454dafba7e191587735c0dc5c6c8… | 2017-02-23 | 2018-01-16 |
| HASH | 3a0fc4cc145eafe20129e9c53aac424… | 2017-02-23 | 2018-01-16 |
| HASH | 7e810cb159fab5baccee7e72708d974… | 2017-02-23 | 2018-01-16 |
| HASH | f080f019073654acbe6b7ab735d3fd2… | 2017-02-23 | 2018-01-16 |
| HASH | 21b098d721ea88bf237c08cdb5c619a… | 2017-02-23 | 2018-01-16 |
| HASH | 930fce7272ede29833abbfb5df4e32e… | 2017-02-23 | 2018-01-16 |
| HASH | 4b20883386665bd205ac50f34f7b629… | 2017-02-23 | 2018-01-16 |