코드 상의 특징을 통해 살펴본 2가지 공격그룹 (한글문서 취약점)

2019-11-18 • Ahnlab • Two attack groups examined through code characteristics (Hangul document vulnerabilities) •

https://asec.ahnlab.com/1265

Thumbnail for 코드 상의 특징을 통해 살펴본 2가지 공격그룹 (한글문서 취약점)

AhnLab ASEC analyzed HWP malware using CVE-2017-8291 and found a recurring coding mistake in the shellcode preparation stage. The error affected a VirtualProtect call but did not prevent execution because the vulnerable Ghostscript processes had DEP disabled. ASEC notes that variants with and without the mistake may indicate two development groups or branches behind related HWP document malware.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d94f26158dc3fd9fd93aa7f38afe63f… 2019-10-20 2021-05-01
HASH 7c5db78537f3a28b9bcfe8f75e86c36… 2019-11-18 2020-11-16
HASH 656d0dc4e7d1da530397b7b140559ea… 2019-11-18 2020-11-16
HASH cf5fd783aa44335ab3108708fb8fb55… 2019-11-18 2019-11-18
HASH a68169aba0691c337241ea1049d8d84… 2019-11-18 2019-11-18
HASH d4f055d170fd783ae4f010df64cfd18… 2019-10-24 2019-11-18
HASH 8182986730b39001807e777469590c2… 2019-07-03 2019-11-18
HASH a283a493138c23a58da445600ea4a73… 2019-05-10 2019-11-18
HASH cd6a12cc693e98e4f47d2161e9fe99d… 2019-02-07 2019-11-18
HASH b2dd7f9bb24428b0e2ed30b9373fe03… 2018-10-24 2019-11-18
HASH a299bdc3fc07def4b0d5a409484f471… 2018-09-13 2019-11-18

Related Reports

« Back