Malicious Hangul (OLE) — malware analysis report

Static analysis result for SHA-256 c9f3e81bfcaec3d4…

MALICIOUS

Hangul (OLE)

16.7 KB First seen: 2020-09-04
MD5: c8130dbf0c6749f478b45f57f43b21c7 SHA-1: 55cf00e6df0d1cd6e55e6f5d7766c2cfc911d4a3 SHA-256: c9f3e81bfcaec3d44fafae0e59da7b1b394226741caee3985a3edffd9b6caf90
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The HWP document contains embedded JavaScript and external URLs, indicating an attempt to redirect the user to malicious content. The JavaScript and embedded URLs suggest the document is designed to exploit user interaction to download or execute further payloads. The presence of these elements strongly points towards a phishing or malware delivery attempt.

Heuristics 4

  • JavaScript detected high HWP_JAVASCRIPT
    HWP document contains JavaScript references
  • External URL medium HWP_URL
    Found 3 URL(s) in document
  • Decompressed OLE-wrapped HWP streams info HWP_COMPRESSED
    Inflated 14835 bytes from BinData / Scripts / BodyText / DocInfo streams of the OLE-wrapped HWP for content analysis
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ro521.com/test.htm HWP document reference
    • http://j5b.kr/bin/h.jsIn document text (OLE body)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
BodyText_Section0 hwp-stream HWP OLE stream: BodyText/Section0 11966 bytes
SHA-256: 324c20c02756128e22b3e456d41bb5031fe5c48dc2bb86b4dea15836b49adc49
DocInfo hwp-stream HWP OLE stream: DocInfo 2589 bytes
SHA-256: d2103855441547d5a2d0c01c02a8140731a62c8f3d945e39711fbefc2886487b
Scripts_DefaultJScript hwp-stream HWP OLE stream: Scripts/DefaultJScript 272 bytes
SHA-256: e1f35ff38336598f79448c84b41bcb508d53a552808454a76ee12691cb2c97e4