OLE 개체를 악용한 HWP 악성코드

2022-06-20 Secu I HWP malware exploiting OLE objects

https://stic.secui.com/main/main/threatInfo?id=45

SECUINSIDE analyzed malicious HWP documents that abused embedded OLE objects rather than patched HWP vulnerabilities to trigger execution through user clicks. The campaign used spear-phishing emails aimed at people connected to North Korea-related topics, with lures such as TV appearance requests and opinion requests. Dropped BAT files launched encoded PowerShell, killed the HWP process, read shellcode from the end of the document, injected it into a new help.exe process, restored a decoy document, and deleted staging files. Two shellcode types were described: one downloaded a script via mshta, while another added C2 encoding, API hashing, and an additional encoded shellcode stage. The final PowerShell payload registered scheduled execution under EstSoft\Alap\Report and communicated with hanainternational[.]net to receive commands, execute them through cmd, exfiltrate results, and collect system information.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://work3.b4a.app/download.… 2022-06-20 2022-07-25
URL http://hanainternational.net/ed… 2022-06-01 2022-07-25
HASH 7847394c36eb24184f74c8610b1c420… 2022-06-20 2022-06-20
HASH ac8388cea848f4ff584a1ffc2b6af7e… 2022-06-20 2022-06-20
URL http://hanainternational.net/ed… 2022-06-20 2022-06-20
HASH a73c3f27b0c6ccb8eddde4c0b9d0089… 2022-06-01 2022-06-20
HASH 7975bbbfcb75dabb3271a8f1a79d67a… 2022-06-01 2022-06-20

Related Reports

« Back