Malicious HWP File with COVID-19 Relief Fund Related ‘Collection of Personal Information Consent Form’

2021-10-28 Ahnlab

https://asec.ahnlab.com/en/28030/

Thumbnail for Malicious HWP File with COVID-19 Relief Fund Related ‘Collection of Personal Information Consent Form’

ASEC found a malicious HWP document disguised as a COVID-19 relief fund personal-information consent form, apparently edited from a legitimate original document. The file used a malicious EPS object containing encoded PostScript and shellcode, reusing malicious RTF and shellcode components previously observed in a cover-letter-themed lure. The shellcode attempted to download additional payloads from gozdeelektronik[.]net paths ending in movie.png and movie.jpg and inject them into explorer.exe, but the payloads were unavailable during analysis. The activity shows continued reuse of older HWP/EPS exploitation techniques and infrastructure patterns, with impact limited on fully patched HWP versions because the EPS vulnerability had been patched in 2017.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://gozdeelektronik.net/wp-… 2019-06-20 2021-10-28
URL https://gozdeelektronik.net/wp-… 2019-06-20 2021-10-28
DOMAIN gozdeelektronik.net 2019-06-20 2021-10-28

Related Reports

« Back