[주의] '2차 북미정상회담' 내용의 한글취약점 문서
2019-02-21 • Ahnlab • [Caution] Hangul vulnerability document related to ‘2nd North Korea-US Summit' •
AhnLab ASEC observed malicious Hangul HWP documents circulating with content related to the upcoming second U.S.–North Korea summit. The documents contained a vulnerable EPS object whose shellcode is decoded with a one-byte XOR key and executed through the normal gswin32c.exe EPS handler on unpatched systems. The shellcode injects into Internet Explorer and attempts to download and run a second-stage DLL from itoassn.mireene.co.kr/shop/shop/mail/com/mun/down[.]php. AhnLab detected the HWP document and downloaded DLL as Trojan/Win32.Hwdoor.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://itoassn.mireene.co.kr/sh… | 2019-02-21 | 2019-02-21 |
| DOMAIN | itoassn.mireene.co.kr | 2019-02-21 | 2019-02-21 |
Related Reports
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab
2026-07-30 •
50% Match
#Phishing
#Ransomware
#Wateringhole
#SIGNBT
#Gunra
#Copperhedge
#DoubleBarrel
Shares tag: Phishing • Same author: Ahnlab
2026-07-30 •
50% Match
Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
Ahnlab
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab
Shares tag: Phishing • Same author: Ahnlab