Malware disguised as company document related to inter-Korean economic cooperation

2018-07-08 • Issuemakers Lab •

http://taylor-blog.issuemakerslab.com/2018/07/malware-disguised-as-company-document.html

Thumbnail for Malware disguised as company document related to inter-Korean economic cooperation

IssueMakersLab reported malware attributed as likely North Korean that used a Korean Word Processor document tied to inter-Korean economic cooperation as the lure. The infection chain used an HWP PostScript vulnerability, shellcode in BIN0002.ps, and an AES-encrypted payload hidden inside a BMP image after the marker string "F0und3g9." The shellcode injected into hwp.exe, searched memory for the embedded marker, decrypted the malware, and executed it by injecting into explorer.exe. The malware collected IP address, computer name, username, locale, Windows version, and CPU information, then communicated with XOR-encoded C2 URLs including pyeonta.com, doosungsys.com, sdajunghwa.com, patentmall.net, and orentcar.com paths. The case matters because HWP is widely used in South Korean public institutions and businesses, making document vulnerabilities a practical delivery route for Korea-focused intrusions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c294520c1f64c77776dad6599da29bf… 2018-07-08 2021-12-21
HASH d060123c21869b765b22b712a8ca472… 2018-07-08 2020-03-09
HASH 6f1bddb3aa221635adfd8b1c465da64… 2018-07-08 2018-07-08
URL http://www.patentmall.net/goods… 2018-07-08 2018-07-08
URL http://sdajunghwa.com/admin/dat… 2018-07-08 2018-07-08
URL http://www.orentcar.com/rental/… 2018-07-08 2018-07-08
URL http://www.pyeonta.com/board/ne… 2018-07-08 2018-07-08
URL http://doosungsys.com/file_bd/u… 2018-07-08 2018-07-08
DOMAIN sdajunghwa.com 2018-07-08 2018-07-08
DOMAIN doosungsys.com 2018-07-08 2018-07-08

Related Reports

« Back