김수키(Kimsuky)만든 링크 방식 악성코드-질문지.doc.lnk(2023.05.08)

2023-05-19 Sakai Link-type malicious code created by Kimsuky - Questionnaire.doc.lnk (2023.05.08)

https://wezard4u.tistory.com/6447

Thumbnail for 김수키(Kimsuky)만든 링크 방식 악성코드-질문지.doc.lnk(2023.05.08)

The source analyzes a Kimsuky-linked LNK malware sample named Questionnaire.doc.lnk that uses a large shortcut file to hide embedded content and launch PowerShell instead of relying on Office macros. The command line searches for the malicious LNK, extracts a decoy PDF named “2023년도 4월 29일 세미나.pdf” into the Temp directory, opens it, then extracts and runs a BAT file named 230415.bat. The lure and execution flow target South Korea-related audiences associated with North Korea policy, while the author notes Kimsuky’s broader aliases and history of using malware families such as Gold Dragon, BabyShark, and AppleSeed. The report provides hashes for the sample, including SHA-256 f92297c4efabba98befeb992a009462d1aba6f3c3a11210a7c054ff5377f0753, and lists antivirus detections for the LNK dropper.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f92297c4efabba98befeb992a009462… 2023-05-01 2023-06-06
HASH aa8ba9a029fa98b868be66b7d46e927b 2023-04-21 2023-05-23
HASH df84ef49d7a50bd04c695489ec5a528… 2023-05-19 2023-05-19

Related Actors

Related Reports

« Back