Malware disguised as company document related to inter-Korean economic cooperation
2018-07-08 • Issuemakers Lab •
http://taylor-blog.issuemakerslab.com/2018/07/malware-disguised-as-company-document.html
IssueMakersLab reported malware attributed as likely North Korean that used a Korean Word Processor document tied to inter-Korean economic cooperation as the lure. The infection chain used an HWP PostScript vulnerability, shellcode in BIN0002.ps, and an AES-encrypted payload hidden inside a BMP image after the marker string "F0und3g9." The shellcode injected into hwp.exe, searched memory for the embedded marker, decrypted the malware, and executed it by injecting into explorer.exe. The malware collected IP address, computer name, username, locale, Windows version, and CPU information, then communicated with XOR-encoded C2 URLs including pyeonta.com, doosungsys.com, sdajunghwa.com, patentmall.net, and orentcar.com paths. The case matters because HWP is widely used in South Korean public institutions and businesses, making document vulnerabilities a practical delivery route for Korea-focused intrusions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3d0355ff78dcc979b3f83a679b6ba794 | 2018-07-08 | 2021-12-21 |
| HASH | a5a71b23e75795fd76153fdf02e7e2ed | 2018-07-08 | 2018-07-08 |
| HASH | d08986b22d2371419dfcdf4abdb821b5 | 2018-07-08 | 2018-07-08 |
| URL | http://www.patentmall.net/goods… | 2018-07-08 | 2018-07-08 |
| URL | http://sdajunghwa.com/admin/dat… | 2018-07-08 | 2018-07-08 |
| URL | http://www.orentcar.com/rental/… | 2018-07-08 | 2018-07-08 |
| URL | http://www.pyeonta.com/board/ne… | 2018-07-08 | 2018-07-08 |
| URL | http://doosungsys.com/file_bd/u… | 2018-07-08 | 2018-07-08 |
| DOMAIN | sdajunghwa.com | 2018-07-08 | 2018-07-08 |
| DOMAIN | doosungsys.com | 2018-07-08 | 2018-07-08 |