Malicious Word Document Being Distributed in Disguise of a News Survey

2022-11-25 Ahnlab

https://asec.ahnlab.com/en/42529/

Thumbnail for Malicious Word Document Being Distributed in Disguise of a News Survey

AhnLab ASEC analyzed a password-protected Word document named CNA[Q].doc, disguised as a Singapore CNA news survey and themed around North Korea-related content. The document relied on a malicious VBA macro that prompted the user to enable content, then dropped and executed tmp.pip from %APPDATA%. The script chain created Defender.log, DefenderUpdate.lba, and Ahnlab.lnk, contacted okihs.mypressonline[.]com for bb.txt and bb.down, collected host information, and downloaded additional scripts. ASEC noted an evolution from earlier variants: the bb.down script used FTP to exfiltrate browser credential material, including Chrome and Edge Local State keys and related browser data, while retaining LNK creation, Office security modification, and keylogging behavior.

Indicators of Compromise

Type Value First Seen Last Seen
URL Http://okihs.mypressonline.com/… 2022-11-25 2022-11-25
HASH 59be2b9a3e33057b3d80574764ab0952 2022-11-16 2022-11-25
HASH 8785b8e882eef125dc527736bb1c5704 2022-11-16 2022-11-25
HASH 89d972f89b336ee07733c72f6f89edc5 2022-11-16 2022-11-25
URL http://okihs.mypressonline.com/… 2022-11-16 2022-11-25
URL http://okihs.mypressonline.com/… 2022-11-16 2022-11-25
URL http://okihs.mypressonline.com/… 2022-11-16 2022-11-25
DOMAIN jojoa.mypressonline.com 2022-11-16 2022-11-25
DOMAIN okihs.mypressonline.com 2022-11-16 2022-11-25

Related Actors

Related Reports

« Back