Malicious Hangul (OLE) — malware analysis report

Static analysis result for SHA-256 c96ba7510daa7fee…

MALICIOUS

Hangul (OLE)

20.7 KB First seen: 2020-08-25
MD5: a2952991c059cc1fd1c606bbcfa614f3 SHA-1: a503e057d63767d9c947ef0f583c804ad1ea1a38 SHA-256: c96ba7510daa7fee097620338bc5c68073ed1a318a0099c56e110af558bf27ac
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The HWP document contains JavaScript, indicated by the HWP_JAVASCRIPT heuristic. This script likely acts as a downloader, fetching a second-stage payload from the embedded URL http://j5b.kr/bin/h.js. The presence of external URLs suggests a malicious intent to retrieve and execute further malicious content, characteristic of a spearphishing attachment.

Heuristics 4

  • JavaScript detected high HWP_JAVASCRIPT
    HWP document contains JavaScript references
  • External URL medium HWP_URL
    Found 3 URL(s) in document
  • Decompressed OLE-wrapped HWP streams info HWP_COMPRESSED
    Inflated 40496 bytes from BinData / Scripts / BodyText / DocInfo streams of the OLE-wrapped HWP for content analysis
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ro521.com/test.htm HWP document reference
    • http://j5b.kr/bin/h.jsIn document text (OLE body)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
BodyText_Section0 hwp-stream HWP OLE stream: BodyText/Section0 34382 bytes
SHA-256: 11aee06f03bc92179023a0eb7bfc3152d2b9c229d2af0f03c1c089198b521779
DocInfo hwp-stream HWP OLE stream: DocInfo 5834 bytes
SHA-256: ccee6c7aa62c258ca78395384c67252cb51466cb5bd76b0fcb9025a94c7cfd6a
Scripts_DefaultJScript hwp-stream HWP OLE stream: Scripts/DefaultJScript 272 bytes
SHA-256: e1f35ff38336598f79448c84b41bcb508d53a552808454a76ee12691cb2c97e4