패스워드 파일로 위장하여 유포 중인 악성코드

2023-03-10 • Ahnlab • Malware distributed disguised as a password file •

https://asec.ahnlab.com/ko/49180/

Thumbnail for 패스워드 파일로 위장하여 유포 중인 악성코드

AhnLab reports Korean-targeted malware distributed in archives that pair password-protected legitimate documents with files masquerading as password information. One CHM variant is assessed as likely tied to RedEyes/APT37/ScarCruft because it reuses commands seen in the group’s M2RAT persistence flow, launching mshta to fetch scripts and register Run-key persistence. The CHM samples contact infrastructure such as shacc.kr and 141.105.65.165 to receive commands and return Base64-encoded results, while a separate LNK variant drops a password text file and VBS script that retrieves additional code from hondes.getenjoyment.net. The report highlights continued abuse of CHM and LNK lures to make victims open malicious helper files alongside benign documents.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://hondes.getenjoyment.net/… 2023-03-10 2024-09-05
DOMAIN hondes.getenjoyment.net 2023-03-10 2024-09-05
HASH 7de166132d700233eaa0fcbe2261a90… 2023-03-10 2023-03-21
URL http://shacc.kr/skin/product/1.… 2023-03-03 2023-03-21
DOMAIN shacc.kr 2023-03-03 2023-03-21
IPv4 141.105.65.165 2023-03-10 2023-03-16
HASH dd56afcce55508fd207144feb1c4f14… 2023-03-10 2023-03-10
HASH ff0d4259510d8b9d6e43cec5224d725… 2023-03-10 2023-03-10

Related Actors

Related Reports

« Back