[Warning] Detected APT attack for Korean famous web portal site (#Update 02)

1. Introduction

INCA Internet response team detected APT type e-mail which is disguised as resume on Korean famous web portal site. This e-mail contains attachment "My resume.doc" which uses CVE-2012-0158 exploit and tries to install another malicious file secretly. If user is exposed by security vulnerability, attacker can collect user PC and user's company's information. 

Usually this kind of attacking method is popular, however, general user hard to recognize of being targeted. Using document file exploit is classical and has been used so far. Users need to be careful on downloading and executing attachment of suspicious e-mail.

INCA Internet response team sent this issue and related information to security manager of that web site.

2. Malicious file attacking procedure and technique

Detail content is as following.

Title : 
FW: Job application

Body :   
Dear (~~):
Good morning. I am honored to be here to get the opportunity to become a potential member of (the name of portal site).
As a college graduate, I believe “where there is a will, there is a way”, and I will try my best to do a good job in my business. So I sincerely hope that I can make a position in your company so that I can serve for the company.
I participated in lots of school activities and social practice during my four years of campus life. And the experience did a good job to improve the skill of communication and enhance the ability of organization. Also, my sense of team spirit is developed. I’m a person who likes challenges.
a. Good command of both oral and writing English, and excellent skills of business negotiation.
b. Special experiences in project coordination, project documentation establishment and management.
c. Able to work under pressure, independent, and strong ability to communicate with various people.
I am enclosing my resume together with my photo, and believe that they may be found satisfactory.. I assure you that if appointed, I will do my best to give your satisfaction.

Very truly yours
That'all,thanks for your attentio

attachment :
My resume.doc

(#Update 02)
Same malicious file has been sent to Japanese company.

Its body is as following.

Hello First joined the company is honored to support.I am a graduate of the University, "Where there is a will there is a way saying," and believe, the company recognized that the people I will do my best. In addition, to thank your company would like to contribute.

During my college participated in various extracurricular activities and community service were the basis of these experiences, as well as communications for organizations to adapt I think.In addition, proficient in team play to know where to enjoy the challenge.

a) Good at English speaking and writing and business negotiations.
b) Project management, and plenty of experience in document creation
c) Ability to handle business on my own good and Excellent communication skills.

I enclosed my resume with a picture. If you give the incident a chance I'll do my best every day.

password: resume

Thank you.

Upon executing malicious attachment "My resume.doc", it will create normal "My resume.doc" on temp folder and run. Its content is as following.

It shows MS Word contents, however, it will create several malicious files for infecting system.

rc.exe is normal MS resource compiler file.

Malicious file tries to access on certain host in Hong Kong, and records key logging history on kl.log.

Following image shows key logging test history. With this file, user's working history can be recorded and leaked.

Malicious file will connect user's PC to certain host in Hong Kong and wait additional command which makes user in danger.

3. Summary

Targeting to a specific organization or company's internal staff to malicious files from infecting computer can't be easily found. Especially for general user, they can't find that they were infected. Therefore, users need to be careful from these security threats. To use PC safely from security threats of these malicious attachments, we recommend you download latest security updates and obey following "Security management tips" for general users.

Security management tips

1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.

INCA Internet (Security Response Center / Emergency Response Team) runs responding system against various security threats.
nProtect Anti-Virus/Spyware v3.0 diagnoses and treats various variant files.

Free installation link of nProtect AVS : http://avs.nprotect.com/


  1. You guys should also check on this article, if you want to find more info on a topic.

  2. Just try not to get caught by this guys. How can I be sure that my site is safe?

  3. Very awesome!!! When I seek for this I found this website at the top of all blogs in search engine

  4. Wow, Really great post i enjoy it very much here I appreciating your knowledge keep sharing kindly check it out (default gateway)

  5. Thanks for this great post. This is really helpful for me. Also, see
    Mobdro for PC Download

  6. Oh! This article has suggested to me many new ideas. I will embark on doing it. Hope you can continue to contribute your talents in this area. Thank you.
    shell shockers

  7. شركة مكافحة النمل الابيض بالرياض  http://tiny.cc/xeph5y  أفضل وأسهل الطرق التي تساعدهم في كيفية التخلص من الحشرات المزعجة وعلى رأسهم حشرة النمل الأبيض، من المعروف أن مكافحة الحشرة بالمبيد الحشري ليسهل عليكِ، يقوم فريق العمل به بكل سهولة كما يعتقد الكثير من الأشخاص، فلا يضرك الكثير أن الاستخدام الخاطئ للمبيد، قد ينتج عنه إصابة الإنسان بالعديد من الأمراض الوخيمة.

    فشركتنا حريصة على أن توفر أجود أنواع المبيدات الحشرية المصرح بها من قبل وزاره الصحة والبيئة التي تملك الفعالية الكبيرة للقضاء نهائياً على هذه الحشرة دون أن تسبب أي ضرر على حياة الإنسان ولا الأيدي العاملة، وفريق عمل الشركة لديه خبرة كبيرة قد اكتسبها عبر السنين، مما أصبح من السهل عليه أن يتعامل مع هذه الحشرة المقززة مهما كانت تختبئ في أماكن دقيقة أو مهما كان عددها كثير، وفريق العمل الخاص بالشركة بعون الله قادر على إبادتها نهائياً فور وصوله إلى المنزل مع ضمان عدم العودة من مكان مرة أخرى، كما أن لدى الشركة فريق عمل خاص لتحصين منزلك من دخول حشرة النمل الأبيض قبل البناء من خلال الأرض قبل وضع الأساس بالمبيد الحشري من هنا عدم وصولها إلى منزلك في أي وقت. … اقرأ المزيد

    المصدر: شركة مكافحة النمل الابيض بالرياض

    شركة تنظيف خزانات بالرياض http://tiny.cc/ceph5y  ان عملية تنظيف الخزانات بالرياض تحتاج الى مهندسين متخصصين فى مجال التنظيف الخاص بالمياه حيث أن المياه تعتبر من الأمور الهامة التى تتعلق بالأسرة كلها حيث أنها مورد يصل الى كل فرد من أفراد الأسرة لذلك عميلنا العزيز عليك بالأهتمام بها .
    حيث يصلك مجموعة من المهندسين المختصين بعملية تنظيف الخزانات ويتم تفريغ الخزان نهائياً والقيام بعملية التنظيف باستخدام مجموعة مواد التنظيف التى تعمل على قتل الجراثيم والبكتريا بنسبة 100% ثم يتم ملىء الخزان مرة أخرى والقيام بعملية الاختبار لبيان مدى نظافة ونقاء المياه.… اقرأ المزيد

    المصدر: شركة تنظيف خزانات بالرياض

  8. If you are using Office setup and getting any issue then you can contact at support.office.com/setup. they will resolve your issue and will help you in the installation process.

  9. I read your post. It is very informative and helpful to me. I admire the message valuable information you provided in your article. Thank you for posting, again!

  10. I love to read books on the internet, and this is one of the best books which is very informative for all of us. I will must buy this book and read it. Web Designer Dubai can help you with designing & the development of your website.

  11. This is a great inspiring article.I am pretty much pleased with your good work.
    You put really very helpful information. Keep it up. Keep blogging Classified Dubai the top classified in UAE company you get opt-in the cheapest prices ever, our dedicated will make sure your ads are classified in Dubai, you will not regret our services ever!

  12. Excellent and A wonderful read! Your article is the best one I have learnt, and it has helped me. Keep doing that. Web Design Training Dubai

  13. Brilliant! This is a really marvellous stuff for me. Must agree that you are one of the coolest blogger. I was curious to see a stuff like that. Fabulous post! Web Design In NYC

  14. Are you struggling with identifying an online Research Papers Writing Services provider which is credible to undertake your Custom Research Paper Writing Service task? Do you know how to access top-rated High Quality Research Paper Writing Services at some clicks from your personal computer?

  15. -Things are very open and intensely clear explanation of issues. was truly information. Your website is very beneficial
    gmail login

  16. For the most part, this sort of assaulting strategy is prevalent, in any case, general clients difficult to perceive being focused on. Utilizing archive record abuse is old style and has been utilized up until this point. Clients should be cautious about downloading and executing the connection of suspicious email.Visit for Commercial Cleaning Services Dubai solid, trusted and disentangled cleaning centre for the Middle East

  17. If you are looking for homework for college students reliable assistance in your university assignments then feel free to contact the professional writers of Allassignmenthelp.com.


  18. custom Cardboard Cigarette boxes and it is an inspiring packaging solution for your product. custom packaging boxes with logo at the wholesale rate with free shipping costs all across the United States and Canada.


  19. كشف تسربات المياه بالاحساء كشف تسربات المياه بالاحساء
    كشف تسربات المياه بالدمام كشف تسربات المياه بالدمام
    كشف تسربات المياه بالرياض كشف تسربات المياه بالرياض

    كشف تسربات المياه بالرياض كشف تسربات بالرياض

    كشف تسربات المياه بالرياض جهاز كشف تسربات المياه بالرياض

  20. chaturbate token currency hack host the most-reliable Chaturbate token generator tool in the entire online market. Our hacking tool provides the best premium tokens for free and for real

    with the help of free coin master you will get a free spin and in spin you can win many coins and you can use those coins in your game..

  21. Die cut box packaging is useful for almost all types of customers but it’s just that their requirements of using these die cut boxes may differ. Every customer uses it according to their own purpose and demands and for that purpose in order to cater to the maximum range of customers, we try to design custom die cut boxes with great variety.
    Custom boxes
    Blank Cigarette boxes
    Empty Cigarette boxes
    Burger boxes
    Bath bomb packaging

  22. The weapon selection bar should appear, but wait until your worm swells to select another weapon. If you don't wait until your worm attacks, the game crashes.

  23. Wales publishers are offering optimized, Best Publication Services in UK to boost the researcher and research communities, by providing accelerated and efficient services to fasten the publishing process and to give more opportunities for research on different disciplines.Wales publication research conferences give the researchers an international platform to discuss their scientific research Open Access Publishing UK work and their edges.We are different from other conferences because the community's member organizes our conferences.

  24. The post is absolutely fantastic. Lots of great information. This is a great post & very useful, are you interest to Hadees Shareef

  25. Thanks for your article.please write on 200ml Box Packaging design elements.

  26. Roku is a streaming device, which is a reasonable roku activation and other Set-up Box. Roku is a bundle of amusement, where client can stream for boundless motion appears, web arrangement, news, animation and a lot more projects.

  27. Really nice sharing, I search many time this type of post. Thanks for sharing, are you interest to
    horror movies in the world

  28. Hi, I hope You are fine. Your work is very good. I read all your published blogs. Your blogs are very informative for me and hope so for everyone. I should be very thankful to you and Your Team. I offered all of You my business which is related to Custom Cream Boxes. My company name is Rush Packaging. We offered to You Custom Boxes all over the World with Free Shipping and Wholesale Rate. We delivered our service on time.
    Custom Cream Boxes
    Custom Hair Extension Boxes
    Custom Lip Balm Boxes
    Custom Mascara Boxes
    Custom Boxes USA

  29. I appreciate your post thanks for sharing the information.
    E Liquid boxes Arizon
    best Eyeliner boxes