MS Media Player 이용한 악성 워드문서 (안랩사칭)

2022-03-31 Ahnlab Malicious word document using MS Media Player (impersonating AhnLab)

https://asec.ahnlab.com/ko/33259/

Thumbnail for MS Media Player 이용한 악성 워드문서 (안랩사칭)

AhnLab ASEC reported malicious Word documents impersonating AhnLab and using cryptocurrency-themed filenames to persuade recipients to enable macros. The initial DOCX fetched an external DOTM template through word/_rels/settings.xml.rels, then used a Windows Media Player open-state event rather than a standard AutoOpen macro to trigger VBA execution. The macro downloaded architecture-specific payloads from naveicoipc[.]tech paths, injected malware into a child word.exe process, and dropped persistence components such as USOService.exe under %ProgramData%\USOShared\Logs with an HKCU Run key. The technique shows continued variation in Korean-language document lures and macro execution methods intended to evade simple AutoOpen-focused detection.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://ZVc1ijAU.naveicoipc.tech… 2022-03-31 2022-03-31
URL http://ZVc1ijAU.naveicoipc.tech… 2022-03-31 2022-03-31
DOMAIN zvc1ijau.naveicoipc.tech 2022-03-31 2022-03-31

Related Reports

« Back