‘2021년 국방부 업무보고 수정’ 문서로 위장한 악성코드 유포

2021-02-03 • Ahnlab • Spreading malicious code disguised as ‘2021 Ministry of Defense Business Report Revision' document •

https://asec.ahnlab.com/ko/20057

Thumbnail for ‘2021년 국방부 업무보고 수정’ 문서로 위장한 악성코드 유포

ASEC observed malware distributed as a PIF executable disguised as a revised 2021 Ministry of National Defense work-report document. When run, the file displayed a legitimate PDF copied from the ministry website while silently dropping a malicious DLL at C:\ProgramData\Intel\Driver\driver.cfg. The DLL was executed with regsvr32.exe and persisted through a scheduled task named Disk0 that ran every 30 minutes. The sample was compiled on January 23, 2021 and was expected to contact attacker-controlled C2 infrastructure at exchange.amikbvx.cf and imap.pamik.cf for further commands, with two hashes and AhnLab detections provided for tracking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 742e04ae5f2cd42cf514abbd1956c59… 2021-02-03 2021-06-23
HASH d16a876029960b1c06272aeaeaaf691… 2021-02-03 2021-02-03
URL http://exchange.amikbvx.cf/ 2021-02-03 2021-02-03
URL http://imap.pamik.cf/ 2021-02-03 2021-02-03
DOMAIN imap.pamik.cf 2021-02-03 2021-02-03
DOMAIN exchange.amikbvx.cf 2021-02-03 2021-02-03

Related Reports

« Back