HWP File Disguised as Personal Profile Form (OLE Object) - ASEC BLOG
Common Information
Type Value
UUID eceae3e7-fe09-407b-b197-b5249cd84c34
Fingerprint 94e3b95b01e7cbaa
Analysis status DONE
Considered CTI value 2
Text language
Published Sept. 5, 2022, 12:51 p.m.
Added to db Sept. 11, 2022, 12:41 p.m.
Last updated Nov. 18, 2024, 1:24 p.m.
Headline HWP File Disguised as Personal Profile Form (OLE Object)
Title HWP File Disguised as Personal Profile Form (OLE Object) - ASEC BLOG
Detected Hints/Tags/Attributes 41/2/26
Source URLs
RSS Feed
Attributes
Details Type #Events CTI Value
Details CVE 59
cve-2018-15982
Details Domain 2
yukkimmo.sportsontheweb.net
Details Domain 3
www.sjem.co.kr
Details File 1212
powershell.exe
Details File 457
mshta.exe
Details File 2
hword.exe
Details File 15
hwp.exe
Details File 2
1234dd.tmp
Details File 2
hw.php
Details File 4
h.txt
Details File 2
2247529.txt
Details File 2130
cmd.exe
Details File 2
%appdata%\12312.txt
Details File 2
3dd21.tmp
Details File 73
view.php
Details md5 2
76f8ccf8313af617df28e8e1f7f39f73
Details md5 2
9a13173df687549cfce3b36d8a4e20d3
Details md5 2
804d12b116bb40282fbf245db885c093
Details md5 2
caa923803152dd9e6b5bf7f6b816ae98
Details md5 2
2f4ed70149da3825be16b6057bf7b8df
Details md5 3
65993d1cb0d1d7ce218fb267ee36f7c1
Details md5 2
330f2f1eb6dc3d753b756a27694ef89b
Details Url 2
http://yukkimmo.sportsontheweb.net/hw.php
Details Url 2
http://yukkimmo.sportsontheweb.net/h.txt
Details Url 2
http://yukkimmo.sportsontheweb.net/2247529.txt
Details Url 3
http://www.sjem.co.kr/admin/data/category/notice_en/view.php