OLE 개체를 악용한 HWP 악성코드
2022-06-20 • Secu I • HWP malware exploiting OLE objects •
SECUINSIDE analyzed malicious HWP documents that abused embedded OLE objects rather than patched HWP vulnerabilities to trigger execution through user clicks. The campaign used spear-phishing emails aimed at people connected to North Korea-related topics, with lures such as TV appearance requests and opinion requests. Dropped BAT files launched encoded PowerShell, killed the HWP process, read shellcode from the end of the document, injected it into a new help.exe process, restored a decoy document, and deleted staging files. Two shellcode types were described: one downloaded a script via mshta, while another added C2 encoding, API hashing, and an additional encoded shellcode stage. The final PowerShell payload registered scheduled execution under EstSoft\Alap\Report and communicated with hanainternational[.]net to receive commands, execute them through cmd, exfiltrate results, and collect system information.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://work3.b4a.app/download.… | 2022-06-20 | 2022-07-25 |
| URL | http://hanainternational.net/ed… | 2022-06-01 | 2022-07-25 |
| HASH | 7847394c36eb24184f74c8610b1c420… | 2022-06-20 | 2022-06-20 |
| HASH | ac8388cea848f4ff584a1ffc2b6af7e… | 2022-06-20 | 2022-06-20 |
| URL | http://hanainternational.net/ed… | 2022-06-20 | 2022-06-20 |
| HASH | a73c3f27b0c6ccb8eddde4c0b9d0089… | 2022-06-01 | 2022-06-20 |
| HASH | 7975bbbfcb75dabb3271a8f1a79d67a… | 2022-06-01 | 2022-06-20 |