건강검진 안내 문서로 위장한 악성코드
2025-11-06 • Logpresso • Malware Disguised as a Health Checkup Notice Document •
https://logpresso.com/en/blog/2025-11-06-healthcheckup-malware
Logpresso assesses that a late-October 2025 attack using a health-check notice lure was conducted by the North Korea-linked Kimsuky group. The intrusion relied on an archive containing a JSE file disguised as a PDF, which displayed a benign document while decoding embedded PE data and loading it through rundll32.exe in the background. The malware contacted its C2 every minute, waited for staged responses such as “live” and “ok,” collected account, host, privilege, systeminfo, and ipconfig data, and uploaded the results with AES-128 and Base64 encoding. A later channel could retrieve an encrypted PE payload, decrypt it with RC4, load an additional DLL, and call a “hello” export, while infrastructure listed in the excerpt includes load.samework.o-r.kr and related o-r.kr/r-e.kr domains.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7d994b591c2d4fafeb3e71278229566e | 2025-11-06 | 2026-02-03 |
| HASH | 5f5f868d339aeb58c613fe7eb55e5432 | 2025-11-06 | 2026-01-14 |
| HASH | 903cec93146327414cbc49068c524292 | 2025-11-06 | 2026-01-14 |
| HASH | d02be241dda3d4027f6fbd84ac015ca8 | 2025-11-06 | 2026-01-14 |
| DOMAIN | mail.naverwork.r-e.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | attach.skyline.r-e.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | gwa.wooritg.o-r.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | rwbcode.com | 2025-11-06 | 2026-01-14 |
| DOMAIN | update.alzip.r-e.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | image.secuwizvpn.r-e.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | load.samework.o-r.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | attach.skycloud.o-r.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | mail.naverwork.o-r.kr | 2025-11-06 | 2026-01-14 |
| DOMAIN | load.rwbcode.com | 2025-11-06 | 2026-01-14 |
| IPv4 | 162.220.11.202 | 2025-11-06 | 2026-01-14 |
| URL | http://load.rwbcode.com/index.p… | 2025-11-06 | 2025-11-06 |
| URL | http://load.samework.o-r.kr/ind… | 2025-11-06 | 2025-11-06 |