Malware/malware analysis 22

์•ฝ๋ ฅ ์–‘์‹.doc #Kimsuky #FlowerPower

IOCs MD5: 00E6F597354D69CDAD7EA5DEEB3C6857 SHA256: E1C09E045AF8B7301390CD9619E3CCA7A96D9D2BBA2B5FC3385A093F3D69B6B4 File name: ์•ฝ๋ ฅ ์–‘์‹.doc File type: DOC File size: 42,653bytes ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ DOC ๋ฌธ์„œ ๋‚ด๋ถ€๋Š” ์•ฝ๋ ฅ ์–‘์‹์ฒ˜๋Ÿผ ์œ„์žฅ ๋งคํฌ๋กœ ์‹คํ–‰์„ ์œ„ํ•œ '์ฝ˜ํ…์ธ  ์‚ฌ์šฉ' ๊ด€๋ จ ์•Œ๋ฆผ ์ฐฝ ⇒ ๋ฌธ์„œ ๋‚ด๋ถ€์— ๋งคํฌ๋กœ๊ฐ€ ์กด์žฌ ๋ถ„์„ ๋ฐฉํ•ด๋ฅผ ์œ„ํ•ด ๋งคํฌ๋กœ ์•”ํ˜ธ ์„ค์ • VBS ๋ฌธ์„œ ์‹คํ–‰ ์‹œ ๋ฐ”๋กœ ์‹คํ–‰๋˜๋Š” Document_Open ํ•จ์ˆ˜ ๋‚œ๋…ํ™”ํ•œ ๋ฌธ์ž์—ด์„ Left, Replace ํ•จ์ˆ˜๋ฅผ ํ†ตํ•ด ๋ณตํ˜ธํ™”ํ•˜์—ฌ ์‚ฌ์šฉ Powershell script #1 ๋ณตํ˜ธํ™”๋œ ๋ฌธ์ž์—ด์€ ํŒŒ์›Œ์‰˜ ์Šคํฌ๋ฆฝํŠธ ์™ธ๋ถ€ URL์— ์ ‘์†ํ•˜..

์งˆ๋ฌธ์ง€.doc #Lazarus

IOCs MD5: BCC12E4C20895DFC52160013AECF76C0 SHA256: 5B81F8F1208D2DFCCB4DD6946102B61AD8F220C7B1C0A80F7BE3CA23E6E59B3E File name: ์งˆ๋ฌธ์ง€.doc File type: DOC File size: 84,480bytes ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ DOC ๋ฌธ์„œ ๋‚ด๋ถ€๋Š” ๋ถํ•œ ๊ด€๋ จ ๋‚ด์šฉ ๋งคํฌ๋กœ ์‹คํ–‰์„ ์œ„ํ•œ '์ฝ˜ํ…์ธ  ์‚ฌ์šฉ' ๊ด€๋ จ ์•Œ๋ฆผ ์ฐฝ ⇒ ๋ฌธ์„œ ๋‚ด๋ถ€์— ๋งคํฌ๋กœ๊ฐ€ ์กด์žฌ VBS #1 ๊ฐ€์žฅ ๋จผ์ € ์‹คํ–‰๋˜๋Š” Document_Open ํ•จ์ˆ˜ ์กฐ๊ฑด(์‹คํ–‰๋˜๊ณ  ์žˆ๋Š” ํŒŒ์ผ ์ด๋ฆ„, VBS ์ด๋ฆ„)์— ๋ถ€ํ•ฉํ•˜๋ฉด ๋ถ„ํ• ๋œ ๋ฐ์ดํ„ฐ๋ฅผ ์กฐํ•ฉ ์กฐํ•ฉ๋œ ๋ฐ์ดํ„ฐ๋Š” BASE64 ์ธ์ฝ”๋”ฉ ๋ฐ์ดํ„ฐ ๋‚ด๋ถ€ ๋ณตํ˜ธ ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ๋””์ฝ”๋”ฉ ๋””์ฝ”๋”ฉ๋œ ๋ฐ์ดํ„ฐ๋Š” ๋˜ ๋‹ค๋ฅธ VBS ์•…์„ฑ์ฝ”๋“œ๋Š” ..