프로필 양식 위장한 한글문서 (OLE개체) - ASEC BLOG
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Mshta - T1218.005 Powershell - T1059.001 Mshta - T1170 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 2b53d80d-6782-47da-85b7-291c22353ba4 |
Fingerprint | 24d2d90be1d6c9ad |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Aug. 29, 2022, 5:52 p.m. |
Added to db | Jan. 16, 2023, 3:56 p.m. |
Last updated | Nov. 18, 2024, 1:24 p.m. |
Headline | 프로필 양식 위장한 한글문서 (OLE개체) |
Title | 프로필 양식 위장한 한글문서 (OLE개체) - ASEC BLOG |
Detected Hints/Tags/Attributes | 14/2/28 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/ko/38216/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 59 | cve-2018-15982 |
|
Details | Domain | 2 | yukkimmo.sportsontheweb.net |
|
Details | Domain | 3 | www.sjem.co.kr |
|
Details | File | 1212 | powershell.exe |
|
Details | File | 457 | mshta.exe |
|
Details | File | 2 | hword.exe |
|
Details | File | 15 | hwp.exe |
|
Details | File | 2 | 1234dd.tmp |
|
Details | File | 2 | hw.php |
|
Details | File | 4 | h.txt |
|
Details | File | 2 | 2247529.txt |
|
Details | File | 2130 | cmd.exe |
|
Details | File | 2 | %appdata%\12312.txt |
|
Details | File | 2 | 3dd21.tmp |
|
Details | File | 73 | view.php |
|
Details | md5 | 2 | 76f8ccf8313af617df28e8e1f7f39f73 |
|
Details | md5 | 2 | 9a13173df687549cfce3b36d8a4e20d3 |
|
Details | md5 | 2 | 804d12b116bb40282fbf245db885c093 |
|
Details | md5 | 2 | caa923803152dd9e6b5bf7f6b816ae98 |
|
Details | md5 | 2 | 2f4ed70149da3825be16b6057bf7b8df |
|
Details | md5 | 3 | 65993d1cb0d1d7ce218fb267ee36f7c1 |
|
Details | md5 | 2 | 330f2f1eb6dc3d753b756a27694ef89b |
|
Details | Url | 2 | http://yukkimmo.sportsontheweb.net/hw.php |
|
Details | Url | 1 | http://yukkimmo.sportsontheweb.net/h.txt에 |
|
Details | Url | 2 | http://yukkimmo.sportsontheweb.net/h.txt |
|
Details | Url | 2 | http://yukkimmo.sportsontheweb.net/2247529.txt |
|
Details | Url | 1 | http://www.sjem.co.kr/admin/data/category/notice_en/view.php로 |
|
Details | Url | 3 | http://www.sjem.co.kr/admin/data/category/notice_en/view.php |