드론(무인항공기) 현황 내용의 한글(*.HWP) 악성코드 유포 중

2020-06-02 • Ahnlab • Spreading Hangul (*.HWP) malware containing drone (unmanned aerial vehicle) status information •

https://asec.ahnlab.com/1328

Thumbnail for 드론(무인항공기) 현황 내용의 한글(*.HWP) 악성코드 유포 중

ASEC observed a malicious Korean HWP document themed around drone and unmanned-aerial-vehicle status information. When opened, the document runs embedded malicious EPS content that abuses CVE-2017-8291 to decode and execute shellcode, checks for AhnLab V3-related processes, and establishes persistence through a scheduled task named OneDrive. The task runs mshta every three minutes to retrieve an HTA payload from www.boaz[.]kr/skin/member/log/pre[.]hta. The source also provides hashes and AhnLab detections for the HWP exploit and downloader chain, making the report useful for tracking HWP/EPS lure delivery and scheduled-task based follow-on execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d3cb1e300d24ed407e35f277f19017c3 2020-06-02 2020-06-02
HASH 79c0fe1467dada33e0b097dd772c362… 2020-06-02 2020-06-02
URL http://www.boaz.kr/skin/member/… 2020-06-02 2020-06-02

Related Reports

« Back