HWP + SlackBot Malware Analysis

2019-11-12 • lysine7 •

https://lysine7.tistory.com/66

Thumbnail for HWP + SlackBot Malware Analysis

The analysis examines two suspicious HWP samples found on VirusTotal that used different filenames but shared the same embedded PostScript component. One lure posed as a new coin listing application and created an executable in the Windows Startup folder from encoded script data. The author notes similarities to known attack patterns that use PostScript in HWP documents to stage payloads for persistence and execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9da1afb59b2e8174650c62ed78681d0… 2019-11-12 2019-11-12
HASH 8004752fd8e192a66fc74ada03018ee… 2019-11-12 2019-11-12
« Back