Malicious Word Document Being Distributed in Disguise of a News Survey
2022-11-25 • Ahnlab •
AhnLab ASEC analyzed a password-protected Word document named CNA[Q].doc, disguised as a Singapore CNA news survey and themed around North Korea-related content. The document relied on a malicious VBA macro that prompted the user to enable content, then dropped and executed tmp.pip from %APPDATA%. The script chain created Defender.log, DefenderUpdate.lba, and Ahnlab.lnk, contacted okihs.mypressonline[.]com for bb.txt and bb.down, collected host information, and downloaded additional scripts. ASEC noted an evolution from earlier variants: the bb.down script used FTP to exfiltrate browser credential material, including Chrome and Edge Local State keys and related browser data, while retaining LNK creation, Office security modification, and keylogging behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | Http://okihs.mypressonline.com/… | 2022-11-25 | 2022-11-25 |
| HASH | 59be2b9a3e33057b3d80574764ab0952 | 2022-11-16 | 2022-11-25 |
| HASH | 8785b8e882eef125dc527736bb1c5704 | 2022-11-16 | 2022-11-25 |
| HASH | 89d972f89b336ee07733c72f6f89edc5 | 2022-11-16 | 2022-11-25 |
| URL | http://okihs.mypressonline.com/… | 2022-11-16 | 2022-11-25 |
| URL | http://okihs.mypressonline.com/… | 2022-11-16 | 2022-11-25 |
| URL | http://okihs.mypressonline.com/… | 2022-11-16 | 2022-11-25 |
| DOMAIN | jojoa.mypressonline.com | 2022-11-16 | 2022-11-25 |
| DOMAIN | okihs.mypressonline.com | 2022-11-16 | 2022-11-25 |