Malicious HWP Document Disguised as Reunification Education Support Application
ID: 2fb79d32-287f-5efe-beaf-18f11812cc34
STIX ID: report--2fb79d32-287f-5efe-beaf-18f11812cc34
Feed Name: ASEC
Threat Score
The AhnLab ASEC report details a malicious HWP document distributed via a public recruitment post that, when opened, extracts a normal HWP plus malicious files (BAT, EXE, manifest, XML), creates files in the TEMP folder, registers Task Scheduler entries for persistence, and downloads/executes additional payloads from an external URL; multiple MD5 hashes and the URL are provided as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
