Distribution of Malware Disguised as Coin and Investment-related Content

2023-08-09 • Ahnlab •

https://asec.ahnlab.com/en/55944/

Thumbnail for Distribution of Malware Disguised as Coin and Investment-related Content

ASEC reports coin exchange and investment-themed malware distributed as SFX executables disguised with Word/PDF icons and as a macro-enabled Word document. The SFX samples opened decoy documents while using mshta.exe to run scripts from partner24.kr paths, and the Word variant copied wscript.exe as word.exe, downloaded a Base64-encoded script from the same infrastructure, and executed it as set.sl. ASEC suspected Kimsuky involvement based on the unusual “Chnome” User-Agent in the macro and shared coin-themed filenames/C2 infrastructure across the samples. Although the final C2 script was unavailable during analysis, the chain could support credential theft, additional malware download, and other operator-directed actions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 928e61590b2c4acf3991bd4327c5107… 2023-07-31 2023-08-09
HASH 51a0d350c910a357476db7079c27d13… 2023-07-31 2023-08-09
HASH 17daf3ea7b80ee95792d4b3332a3390d 2023-07-31 2023-08-09
HASH de4cac7950d1bb99c86ab9ac86d94c3… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09

Related Actors

Related Reports

« Back