김수키(Kimsuky)암호화폐 거래소 업비트 사칭 악성코드-Upbit_20240916 docx lnk(2024.9.17)

2024-09-20 Sakai Kimsuky malware impersonating the Upbit cryptocurrency exchange through DOCX and LNK lures

https://wezard4u.tistory.com/429281

Thumbnail for 김수키(Kimsuky)암호화폐 거래소 업비트 사칭 악성코드-Upbit_20240916 docx lnk(2024.9.17)

Kimsuky is linked in the excerpt to a malicious LNK file disguised as an Upbit cryptocurrency-exchange document, with SHA-256 41cf6298a41c27357ee5f70d8cd1c0bd48698fc30c4255fad6a91798286e5229. The shortcut uses mshta.exe to launch obfuscated JavaScript and PowerShell, bypass execution policy, connect to 64.49.14.181:8014, decode a Base64 ZIP into ProgramData, extract it, and run s.vbs. Follow-on script content creates scheduled-task and Run-key persistence, opens a decoy DOCX, and executes PowerShell from temporary files. A later payload establishes TCP command handling against 64.49.14.181 on port 7032, writes received commands to tmps2.ps1, executes them with PowerShell, and deletes the temporary script, giving defenders concrete lure, persistence, C2, and hash indicators to hunt.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 64.49.14.181 2024-09-17 2024-09-26
HASH 4434d291290fbc40b0b4f323f647496… 2024-09-20 2024-09-20
HASH 7b5783d42240651af78ebf7e01b31fe8 2024-09-20 2024-09-20
HASH f43373ad8d860b4e86e6ce82a65b99ee 2024-09-20 2024-09-20
HASH 6564c5e2e6193e6a947f00881a92c1a… 2024-09-20 2024-09-20
HASH dbb2a7fd1f1653cbec4f8d4b627bef5… 2024-09-20 2024-09-20
HASH eabfadb9034062fed3d32dc290e3284… 2024-09-20 2024-09-20
HASH 69e038480a7b38ac62d7df0c416e83c… 2024-09-20 2024-09-20
HASH 1a1723be720c1d9cd57cf4a6a112df79 2024-09-20 2024-09-20
HASH c4aba442d881cfa112fe3a6b1d2381b… 2024-09-20 2024-09-20
HASH ea96a61215ac44e295a19d3ede58e9b… 2024-09-20 2024-09-20
HASH 963af57641c094df6b5656552daaafd… 2024-09-20 2024-09-20
HASH b500b170146308722a95b6892fbdf88… 2024-09-20 2024-09-20
HASH 6c510785cf239cafcaf5ebf8d588689f 2024-09-20 2024-09-20
HASH 40756e44f5721dbb8d17bc538336d15… 2024-09-20 2024-09-20
HASH 37fb639a295daa760c739bc21c553406 2024-09-17 2024-09-20
HASH 0c3fd7f45688d5ddb9f0107877ce2fbd 2024-09-17 2024-09-20
HASH 50e4d8a112e4aad2c984d22f83c80c8… 2024-09-17 2024-09-20
HASH 41cf6298a41c27357ee5f70d8cd1c0b… 2024-09-17 2024-09-20

Related Actors

Related Reports

« Back