코인 및 투자 관련 내용으로 위장한 악성코드 유포 중

2023-07-31 • Ahnlab • Spreading malware disguised as coin and investment-related content •

https://asec.ahnlab.com/ko/55646/

Thumbnail for 코인 및 투자 관련 내용으로 위장한 악성코드 유포 중

ASEC observed malware disguised as cryptocurrency exchange and investment material, with User-Agent artifacts leading it to assess Kimsuky involvement. The campaign used SFX executables with Word/PDF icons to open decoy asset-management or coin-exchange documents while invoking mshta.exe against partner24.kr script paths. A related macro Word document copied wscript.exe to AppData as word.exe, downloaded Base64-encoded script content from partner24.kr/mokozy/hope/kk.php, wrote it as set.sl, and launched it with VBScript. Although the final payload was unavailable during analysis, the delivery chain could support information theft or additional malware download; ASEC listed partner24.kr URLs and MD5 hashes as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 928e61590b2c4acf3991bd4327c5107… 2023-07-31 2023-08-09
HASH 51a0d350c910a357476db7079c27d13… 2023-07-31 2023-08-09
HASH 17daf3ea7b80ee95792d4b3332a3390d 2023-07-31 2023-08-09
HASH de4cac7950d1bb99c86ab9ac86d94c3… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09

Related Actors

Related Reports

« Back