Malicious Hangul (OLE) — malware analysis report

Static analysis result for SHA-256 a066a30a36739d8e…

MALICIOUS

Hangul (OLE)

2.26 MB First seen: 2018-02-19
MD5: 4877feee41a3faff6b59b82a63c563d4 SHA-1: 9ea027a4cefaca6d927345167d0b997c3e3de54d SHA-256: a066a30a36739d8e50416f4a5dddfd6c5b37423747d1d09810d71694d1f3e1ff
84 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The sample is an HWP document that contains JavaScript, indicating a likely attempt to execute malicious code. The presence of shellcode candidate regions in extracted artifacts further supports this. While several URLs were extracted, they are all confirmed as benign. The JavaScript's specific function is not fully discernible due to obfuscation, but it is presumed to download a secondary payload, consistent with a malicious document delivered via spearphishing.

Heuristics 5

  • JavaScript detected high HWP_JAVASCRIPT
    HWP document contains JavaScript references
  • External URL medium HWP_URL
    Found 20 URL(s) in document
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Decompressed OLE-wrapped HWP streams info HWP_COMPRESSED
    Inflated 10339932 bytes from BinData / Scripts / BodyText / DocInfo streams of the OLE-wrapped HWP for content analysis
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/ HWP document reference
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In document text (OLE body)
    • http://ns.adobe.com/iX/1.0/In document text (OLE body)
    • http://ns.adobe.com/xap/1.0/mm/In document text (OLE body)

Extracted artifacts 32

Files carved from inside the sample during analysis.

FilenameKindSourceSize
BinData_BIN0001.JPG hwp-stream HWP OLE stream: BinData/BIN0001.JPG 147415 bytes
SHA-256: 509b8b79093ed3235130db58a96e59c9ec4f2e0d0e75166608df3306b087b3ff
BinData_BIN0002.JPG hwp-stream HWP OLE stream: BinData/BIN0002.JPG 24441 bytes
SHA-256: 7a3ac160c3f30c41641fe3ddb133c98955a1222fe7cf2312007851e498db15f1
BinData_BIN0003.JPG hwp-stream HWP OLE stream: BinData/BIN0003.JPG 83625 bytes
SHA-256: b0907a42ae59f5d38f9a1cb70f364875f55ac85277bcd240430e7e0bff039e19
BinData_BIN0004.wmf hwp-stream HWP OLE stream: BinData/BIN0004.wmf 10348 bytes
SHA-256: a17a6a2686e03b433d869eb77408d07afc716dabb504360c2885e5fea4771e9e
BinData_BIN0005.wmf hwp-stream HWP OLE stream: BinData/BIN0005.wmf 10464 bytes
SHA-256: 11c144fb79ed1e603b2ca396cf3690e2e73c2acdc76172e2c9b85b6e27ba05ec
BinData_BIN0006.BMP hwp-stream HWP OLE stream: BinData/BIN0006.BMP 774054 bytes
SHA-256: 1b46b8e0774f60c0e645aabcc9cef626b1827b4217e5a44a0b71670b3ed4ffea
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled
BinData_BIN0007.BMP hwp-stream HWP OLE stream: BinData/BIN0007.BMP 774054 bytes
SHA-256: 025d0f738b6a9db95abd115d72d8d778558a3971c097b03124f5ce824241716e
BinData_BIN0008.BMP hwp-stream HWP OLE stream: BinData/BIN0008.BMP 774054 bytes
SHA-256: d62dc64ae5496d4d5d9d8726906c709d4a4315643b8337637197dbb7a4a32a45
BinData_BIN0009.BMP hwp-stream HWP OLE stream: BinData/BIN0009.BMP 774054 bytes
SHA-256: 5f93f31d02fcc54018fe833936c1b5ba5ad8a3aa753c2a2b3ab66da9ad770388
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled
BinData_BIN000A.BMP hwp-stream HWP OLE stream: BinData/BIN000A.BMP 774054 bytes
SHA-256: 7248a6c5c919381de3d20d16c416af725956a701d44aceacefbc23820db09a6b
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled
BinData_BIN000B.bmp hwp-stream HWP OLE stream: BinData/BIN000B.bmp 591062 bytes
SHA-256: aacc6d37479df94d33d3710db62c3bf9a942fb7d831ad8dac2ac11da3eb5ff54
BinData_BIN000C.bmp hwp-stream HWP OLE stream: BinData/BIN000C.bmp 220918 bytes
SHA-256: 073c6dda885843848b670cff993ce0bb750d37a5b9e13c494c1641bb0190897c
BinData_BIN000D.bmp hwp-stream HWP OLE stream: BinData/BIN000D.bmp 283054 bytes
SHA-256: d1572c3da99886565d6fcb490ba4388819b1e03560d0d6bc90b2d9a50966f846
BinData_BIN000E.bmp hwp-stream HWP OLE stream: BinData/BIN000E.bmp 525838 bytes
SHA-256: 4520a1cb3bb248d0fa2d0c4bc4433a6770c71e674124f3a78f16fc3fc68deb11
BinData_BIN000F.bmp hwp-stream HWP OLE stream: BinData/BIN000F.bmp 320470 bytes
SHA-256: f86b8eb2d316a195e3fc636a9c0d493bdd8c5531ab39d0be81096f2cf95f5afe
BinData_BIN0010.OLE hwp-stream HWP OLE stream: BinData/BIN0010.OLE 8708 bytes
SHA-256: 19b702ee234ed9a4963a7c26e68ce9bf246539be1f2f633047a781cd78528007
BinData_BIN0011.OLE hwp-stream HWP OLE stream: BinData/BIN0011.OLE 14340 bytes
SHA-256: 84174cd1c4632a0307dad05fff3cfbfe3c54d139b85f811df5934e7db4ab7dcc
BinData_BIN0012.OLE hwp-stream HWP OLE stream: BinData/BIN0012.OLE 13828 bytes
SHA-256: 28ebf55ad84dd67be88db5d3a800f72ef2c1879aa358c6da6e172c7598b9375d
BinData_BIN0013.WMF hwp-stream HWP OLE stream: BinData/BIN0013.WMF 72284 bytes
SHA-256: 4bad62e52b5eede3eb22a9b72969a20606ebd284510558b5cd503d061a54d17c
BinData_BIN0014.WMF hwp-stream HWP OLE stream: BinData/BIN0014.WMF 4880 bytes
SHA-256: df4b38604353fe88d789d2f3746744eba5a77ffba87b5d1fd5c08394ccf3476a
BinData_BIN0015.JPG hwp-stream HWP OLE stream: BinData/BIN0015.JPG 51940 bytes
SHA-256: c8ba535dc2dcbf3b81c316f57cc7ffa6da417af49e7e4d1fb11ffc25dbe29747
BinData_BIN0016.JPG hwp-stream HWP OLE stream: BinData/BIN0016.JPG 51322 bytes
SHA-256: ff5e45d5736735eff19015cc06b710a7b6e9550d289ac47abb1fd34865438baa
BinData_BIN0017.JPG hwp-stream HWP OLE stream: BinData/BIN0017.JPG 63964 bytes
SHA-256: c56ebf899e9e5435157c6f16627b11bf489c676df7d2578a39ecafd400aa08b3
BinData_BIN0018.JPG hwp-stream HWP OLE stream: BinData/BIN0018.JPG 51971 bytes
SHA-256: 374096935830fee72efbab4369df0080bb4d867700cb70c9ac258c6ed9b7de75
BinData_BIN0019.JPG hwp-stream HWP OLE stream: BinData/BIN0019.JPG 44017 bytes
SHA-256: 6a2b9e98af1d270040254719631dbb6974ef11dc8de4566d43387f9be8a8605e
BinData_BIN001A.jpg hwp-stream HWP OLE stream: BinData/BIN001A.jpg 24823 bytes
SHA-256: 4c95c3982b607e3582eea1669d53a213fd8bfc19b77f737cf97327541412fe32
BinData_BIN001B.bmp hwp-stream HWP OLE stream: BinData/BIN001B.bmp 40164 bytes
SHA-256: 8014e7e84fd8ba6a93550845c58e8a76cc255b6188c6d4fb249797cf38078940
BinData_BIN001C.jpg hwp-stream HWP OLE stream: BinData/BIN001C.jpg 14129 bytes
SHA-256: 3d1d174827536665b3c6f24d6af92e86c0c0fbdafe27b992ef7c3a49e755b657
BinData_BIN001D.jpg hwp-stream HWP OLE stream: BinData/BIN001D.jpg 27630 bytes
SHA-256: 8150883ad20e42a8c9061f090573e5d9aa190aba9ccc8bbcc188d2ec8bbf605f
BinData_BIN001E.jpg hwp-stream HWP OLE stream: BinData/BIN001E.jpg 20297 bytes
SHA-256: 83c6d2923c543876323507f3b3e953a18988300a9a4a0ba16939b7f67c8c48ae
BinData_BIN001F.jpg hwp-stream HWP OLE stream: BinData/BIN001F.jpg 50579 bytes
SHA-256: d2e512f6f1692506656e9db15243f744d7df165f26c7ea53f19508616f00b288
BinData_BIN0020.jpg hwp-stream HWP OLE stream: BinData/BIN0020.jpg 365440 bytes
SHA-256: 0f6632e5c89ff6cb275a629ef16028c4f6a716bd09c59ed9f8bef69ed0b82a8e