Distribution of Malware Disguised as Coin and Investment-related Content
2023-08-09 • Ahnlab •
ASEC reports coin exchange and investment-themed malware distributed as SFX executables disguised with Word/PDF icons and as a macro-enabled Word document. The SFX samples opened decoy documents while using mshta.exe to run scripts from partner24.kr paths, and the Word variant copied wscript.exe as word.exe, downloaded a Base64-encoded script from the same infrastructure, and executed it as set.sl. ASEC suspected Kimsuky involvement based on the unusual “Chnome” User-Agent in the macro and shared coin-themed filenames/C2 infrastructure across the samples. Although the final C2 script was unavailable during analysis, the chain could support credential theft, additional malware download, and other operator-directed actions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 928e61590b2c4acf3991bd4327c5107… | 2023-07-31 | 2023-08-09 |
| HASH | 51a0d350c910a357476db7079c27d13… | 2023-07-31 | 2023-08-09 |
| HASH | 17daf3ea7b80ee95792d4b3332a3390d | 2023-07-31 | 2023-08-09 |
| HASH | de4cac7950d1bb99c86ab9ac86d94c3… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |