건강검진 안내 문서로 위장한 악성코드

2025-11-06 Logpresso Malware Disguised as a Health Checkup Notice Document

https://logpresso.com/en/blog/2025-11-06-healthcheckup-malware

Thumbnail for 건강검진 안내 문서로 위장한 악성코드

Logpresso assesses that a late-October 2025 attack using a health-check notice lure was conducted by the North Korea-linked Kimsuky group. The intrusion relied on an archive containing a JSE file disguised as a PDF, which displayed a benign document while decoding embedded PE data and loading it through rundll32.exe in the background. The malware contacted its C2 every minute, waited for staged responses such as “live” and “ok,” collected account, host, privilege, systeminfo, and ipconfig data, and uploaded the results with AES-128 and Base64 encoding. A later channel could retrieve an encrypted PE payload, decrypt it with RC4, load an additional DLL, and call a “hello” export, while infrastructure listed in the excerpt includes load.samework.o-r.kr and related o-r.kr/r-e.kr domains.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7d994b591c2d4fafeb3e71278229566e 2025-11-06 2026-02-03
HASH 5f5f868d339aeb58c613fe7eb55e5432 2025-11-06 2026-01-14
HASH 903cec93146327414cbc49068c524292 2025-11-06 2026-01-14
HASH d02be241dda3d4027f6fbd84ac015ca8 2025-11-06 2026-01-14
DOMAIN mail.naverwork.r-e.kr 2025-11-06 2026-01-14
DOMAIN attach.skyline.r-e.kr 2025-11-06 2026-01-14
DOMAIN gwa.wooritg.o-r.kr 2025-11-06 2026-01-14
DOMAIN rwbcode.com 2025-11-06 2026-01-14
DOMAIN update.alzip.r-e.kr 2025-11-06 2026-01-14
DOMAIN image.secuwizvpn.r-e.kr 2025-11-06 2026-01-14
DOMAIN load.samework.o-r.kr 2025-11-06 2026-01-14
DOMAIN attach.skycloud.o-r.kr 2025-11-06 2026-01-14
DOMAIN mail.naverwork.o-r.kr 2025-11-06 2026-01-14
DOMAIN load.rwbcode.com 2025-11-06 2026-01-14
IPv4 162.220.11.202 2025-11-06 2026-01-14
URL http://load.rwbcode.com/index.p… 2025-11-06 2025-11-06
URL http://load.samework.o-r.kr/ind… 2025-11-06 2025-11-06

Related Actors

Related Reports

« Back