코인 및 투자 관련 내용으로 위장한 악성코드 유포 중
2023-07-31 • Ahnlab • Spreading malware disguised as coin and investment-related content •
ASEC observed malware disguised as cryptocurrency exchange and investment material, with User-Agent artifacts leading it to assess Kimsuky involvement. The campaign used SFX executables with Word/PDF icons to open decoy asset-management or coin-exchange documents while invoking mshta.exe against partner24.kr script paths. A related macro Word document copied wscript.exe to AppData as word.exe, downloaded Base64-encoded script content from partner24.kr/mokozy/hope/kk.php, wrote it as set.sl, and launched it with VBScript. Although the final payload was unavailable during analysis, the delivery chain could support information theft or additional malware download; ASEC listed partner24.kr URLs and MD5 hashes as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 928e61590b2c4acf3991bd4327c5107… | 2023-07-31 | 2023-08-09 |
| HASH | 51a0d350c910a357476db7079c27d13… | 2023-07-31 | 2023-08-09 |
| HASH | 17daf3ea7b80ee95792d4b3332a3390d | 2023-07-31 | 2023-08-09 |
| HASH | de4cac7950d1bb99c86ab9ac86d94c3… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |