Warning Against HWP Documents Embedded with Malicious OLE Objects

2023-11-01 Ahnlab

https://asec.ahnlab.com/en/58335/

Thumbnail for Warning Against HWP Documents Embedded with Malicious OLE Objects

AhnLab identified malicious HWP documents embedded with OLE objects and aimed at people in sectors including national defense, unification, education, and the press. One document type triggered external URLs through oversized embedded OLE objects, while another created batch and text files in the temporary folder and used PowerShell to fetch scripts from GitHub. The scripts collected recent-file lists, network configuration, and running processes, stored the results under the user's AppData path, and uploaded them to an attacker-controlled FTP server. Persistence was maintained by creating an LNK file in the Startup folder that re-executed a PowerShell command to retrieve the GitHub-hosted script after reboot. The infrastructure cited includes host.sharingdocument[.]one, mail.smartprivacyc[.]com, raw.githubusercontent[.]com/babaramam/repo, and plm.myartsonline[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2f0a67b719d8303c0ec7cc9057ed8411 2023-10-27 2023-11-01
HASH a242741873637fdac8f69f2ffdba47bc 2023-10-27 2023-11-01
HASH 2ef182bced72da507d2e403ab9db3c9f 2023-10-27 2023-11-01
HASH 0217e70fd7bc3a65ee0f2dd60ff85fbf 2023-10-27 2023-11-01
HASH c16796909d5feea709d99e306f7e9975 2023-10-27 2023-11-01
HASH 8cafe74f03605a9bfaea5081b3ed0fc2 2023-10-27 2023-11-01
HASH 2773acee87413790e9ace99c536c78ad 2023-10-27 2023-11-01
HASH f416b44332b4fb394b4735634cb07ff2 2023-10-27 2023-11-01
HASH 77edb140b86596eabe3602bb7febb997 2023-10-27 2023-11-01
HASH 1061425d7e3d054a79f9294a2118b5da 2023-10-27 2023-11-01
HASH af5bbab33f934dc016fc1aa0d910820e 2023-10-27 2023-11-01
HASH 4934226f319d82ae092ada2525a7feb5 2023-10-27 2023-11-01
HASH 7284a6376aa79a2384f797769b7ce086 2023-10-27 2023-11-01
HASH 7f3a30525b9324a2aeb32a9018df944f 2023-10-27 2023-11-01
HASH 361237b6b385874f02f3724ae50d1522 2023-10-27 2023-11-01
HASH d5d395d90ccf9a7309f2f64169a2c019 2023-10-27 2023-11-01
URL http://mail.smartprivacyc.com/g… 2023-10-27 2023-11-01
URL http://host.sharingdocument.one… 2023-10-27 2023-11-01
DOMAIN host.sharingdocument.one 2023-10-27 2023-11-01
DOMAIN mail.smartprivacyc.com 2023-10-27 2023-11-01
DOMAIN plm.myartsonline.com 2023-10-27 2023-11-01

Related Reports

« Back