취약점 한글파일을 이용한 MBR 파괴기능의 악성코드 등장
2014-12-10 • Ahnlab • Appearance of malicious code with MBR destruction function using vulnerability Hangul file •
AhnLab analyzed nine malicious Hangul Word Processor documents that used a known HWP vulnerability and were reportedly distributed as email attachments to specific recipients. Each document carried the same malicious file, which installed a DLL under the system directory as a randomly named Windows service and included both backdoor-style behavior and destructive functions. The payload used a registry value and local system time check to decide when to overwrite the MBR, replacing 512 bytes and showing a “Who Am I?” message on reboot. It also searched drive letters A through Z for selected file extensions and truncated matching files to 4 KB filled with null bytes. The report provides MD5 hashes for the exploit documents and the Win32 destroyer payload, supporting defensive validation and detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ba08b13577eef393db69a20d9b881bf… | 2014-12-10 | 2019-03-04 |
| HASH | 4ee3b3c45e3bd55613cf6727e000664… | 2014-12-10 | 2014-12-23 |
| HASH | 9c907e254f1723b0a32e4fe1d1636ca… | 2014-12-10 | 2014-12-23 |
| HASH | 226b3e4f4f3c48ab33e4759da1c025f… | 2014-12-10 | 2014-12-23 |
| HASH | 6644aa302772ed8b926f0714b407539… | 2014-12-10 | 2014-12-23 |
| HASH | a624f9653b005c2e71f1a65ebe4de1f… | 2014-12-10 | 2014-12-23 |
| HASH | ead682b889218979b1f2f1527227af9b | 2014-12-10 | 2014-12-23 |
| HASH | 9f6d9673c3ae3e4a5c7f64f5ffdf36b… | 2014-12-10 | 2014-12-23 |
| HASH | f809287e23fbe52dff63702477b7b67… | 2014-12-10 | 2014-12-23 |
| HASH | f3ec8db8b1f52eba733478fbd28debd… | 2014-12-10 | 2014-12-23 |