취약점 한글파일을 이용한 MBR 파괴기능의 악성코드 등장

2014-12-10 • Ahnlab • Appearance of malicious code with MBR destruction function using vulnerability Hangul file •

http://asec.ahnlab.com/1015

Thumbnail for 취약점 한글파일을 이용한 MBR 파괴기능의 악성코드 등장

AhnLab analyzed nine malicious Hangul Word Processor documents that used a known HWP vulnerability and were reportedly distributed as email attachments to specific recipients. Each document carried the same malicious file, which installed a DLL under the system directory as a randomly named Windows service and included both backdoor-style behavior and destructive functions. The payload used a registry value and local system time check to decide when to overwrite the MBR, replacing 512 bytes and showing a “Who Am I?” message on reboot. It also searched drive letters A through Z for selected file extensions and truncated matching files to 4 KB filled with null bytes. The report provides MD5 hashes for the exploit documents and the Win32 destroyer payload, supporting defensive validation and detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ba08b13577eef393db69a20d9b881bf… 2014-12-10 2019-03-04
HASH 4ee3b3c45e3bd55613cf6727e000664… 2014-12-10 2014-12-23
HASH 9c907e254f1723b0a32e4fe1d1636ca… 2014-12-10 2014-12-23
HASH 226b3e4f4f3c48ab33e4759da1c025f… 2014-12-10 2014-12-23
HASH 6644aa302772ed8b926f0714b407539… 2014-12-10 2014-12-23
HASH a624f9653b005c2e71f1a65ebe4de1f… 2014-12-10 2014-12-23
HASH ead682b889218979b1f2f1527227af9b 2014-12-10 2014-12-23
HASH 9f6d9673c3ae3e4a5c7f64f5ffdf36b… 2014-12-10 2014-12-23
HASH f809287e23fbe52dff63702477b7b67… 2014-12-10 2014-12-23
HASH f3ec8db8b1f52eba733478fbd28debd… 2014-12-10 2014-12-23

Related Reports

« Back