포스트스크립트를 이용한 HWP 한글 문서 악성코드 주의

2020-04-28 • Ahnlab • Beware of malware in HWP Hangul documents using PostScript •

https://asec.ahnlab.com/1315

Thumbnail for 포스트스크립트를 이용한 HWP 한글 문서 악성코드 주의

ASEC warned that HWP malware using Encapsulated PostScript objects had increased in April 2020, including lures impersonating COVID-19 infection-control organizations and Korea Hydro & Nuclear Power recruitment notices. The attacker inserted malicious EPS content into otherwise normal-looking Hangul documents and simplified the PostScript syntax so that CVE-2017-8291 exploitation and shellcode execution were hidden inside hexadecimal data executed with cvx and exec. The payloads downloaded files from external servers, saved them under image-like names such as skype.jpg or photo.jpg, and executed them with regsvr32 or saved another download as svchost.exe for execution. The report emphasizes that the simplified PostScript pattern made detection harder and required behavioral and exploit-focused detection rather than relying only on visible document content.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 67a52dbb1067cc4546bb738cc5a77a4… 2020-04-28 2020-04-28
HASH cbedf01fa62a94219e70dae13d3dc984 2020-04-28 2020-04-28
URL http://matteoragazzini.it/wp-co… 2020-04-28 2020-04-28
URL https://matteoragazzini.it/wp-c… 2020-04-28 2020-04-28
DOMAIN matteoragazzini.it 2020-04-28 2020-04-28
HASH eae3dc403d36b115aa4f7db64cb1a64… 2020-04-15 2020-04-28
URL http://teslacontrols.ir/wp-incl… 2020-04-15 2020-04-28
URL http://teslacontrols.ir/wp-incl… 2020-04-15 2020-04-28
DOMAIN teslacontrols.ir 2020-04-15 2020-04-28

Related Reports

« Back