공격자 메일에 회신한 경우에 외부 링크로 제공되는 워드문서 (Kimsuky)
2022-07-26 • Ahnlab • Word documents delivered through external links after replying to attacker emails (Kimsuky) •
AhnLab reported continued Kimsuky distribution of malicious Word documents themed around North Korea-related work, including resume, interim-report, advisory-request, and webinar lures. In one flow, the attacker impersonated a domestic organization and only sent an external download link after the recipient replied positively to the initial email, leading through a credential-harvesting URL and likely document download path. The documents used Korean macro-enable decoy images and VBA macros that created a version.ini script or copied mshta.exe to gtfmon.exe, then attempted to contact asssambly.mywebcommunity[.]org or freunkown1.sportsontheweb[.]net. AhnLab warns that the activity reflects persistent Kimsuky use of socially engineered Word documents and external links against users handling DPRK-related topics.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | freunkown1.sportsontheweb.net | 2022-07-26 | 2022-07-29 |
| HASH | 282d7abf5b1a6d86f1c905572101997… | 2022-07-26 | 2022-07-26 |
| HASH | e59f0aa13e2da2a0cd5c07e882014d9… | 2022-07-26 | 2022-07-26 |
| URL | http://freunkown1.sportsonthewe… | 2022-07-26 | 2022-07-26 |
| URL | http://asssambly.mywebcommunity… | 2022-07-26 | 2022-07-26 |
| URL | https://accounts.serviceprotect… | 2022-07-26 | 2022-07-26 |
| DOMAIN | asssambly.mywebcommunity.org | 2022-07-26 | 2022-07-26 |
| DOMAIN | accounts.serviceprotect.eu | 2022-07-26 | 2022-07-26 |