Malware disguised as company document related to inter-Korean economic cooperation

2018-07-08 Issuemakers Lab

http://taylor-blog.issuemakerslab.com/2018/07/malware-disguised-as-company-document.html

Thumbnail for Malware disguised as company document related to inter-Korean economic cooperation

IssueMakersLab reported malware attributed as likely North Korean that used a Korean Word Processor document tied to inter-Korean economic cooperation as the lure. The infection chain used an HWP PostScript vulnerability, shellcode in BIN0002.ps, and an AES-encrypted payload hidden inside a BMP image after the marker string "F0und3g9." The shellcode injected into hwp.exe, searched memory for the embedded marker, decrypted the malware, and executed it by injecting into explorer.exe. The malware collected IP address, computer name, username, locale, Windows version, and CPU information, then communicated with XOR-encoded C2 URLs including pyeonta.com, doosungsys.com, sdajunghwa.com, patentmall.net, and orentcar.com paths. The case matters because HWP is widely used in South Korean public institutions and businesses, making document vulnerabilities a practical delivery route for Korea-focused intrusions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3d0355ff78dcc979b3f83a679b6ba794 2018-07-08 2021-12-21
HASH a5a71b23e75795fd76153fdf02e7e2ed 2018-07-08 2018-07-08
HASH d08986b22d2371419dfcdf4abdb821b5 2018-07-08 2018-07-08
URL http://www.patentmall.net/goods… 2018-07-08 2018-07-08
URL http://sdajunghwa.com/admin/dat… 2018-07-08 2018-07-08
URL http://www.orentcar.com/rental/… 2018-07-08 2018-07-08
URL http://www.pyeonta.com/board/ne… 2018-07-08 2018-07-08
URL http://doosungsys.com/file_bd/u… 2018-07-08 2018-07-08
DOMAIN sdajunghwa.com 2018-07-08 2018-07-08
DOMAIN doosungsys.com 2018-07-08 2018-07-08

Related Reports

« Back