김수키(Kimsuky)에서 만든 고속국도 제29호선 세종-안성 간 건설공사 송장으로 위장 하는 악성코드-도x기업 20240610 송장.bmp.lnk(2024.7.30)

2024-08-26 Sakai Malware Created by Kimsuky Disguised as an Invoice for the Sejong-Anseong Construction Work on Expressway No. 29 - Do X Company 20240610 Invoice.bmp.lnk (2024.7.30)

http://wezard4u.tistory.com/429261

Thumbnail for 김수키(Kimsuky)에서 만든 고속국도 제29호선 세종-안성 간 건설공사 송장으로 위장 하는 악성코드-도x기업 20240610 송장.bmp.lnk(2024.7.30)

A Kimsuky linked archive used a highway construction invoice theme and hid an LNK file behind a BMP filename, "Do-yang Company 20240610 invoice cover.bmp.lnk". The shortcut runs hidden PowerShell, decodes a Base64 command, downloads a decoy BMP from Dropbox, and writes chrome.ps1 under AppData. It then registers a hidden scheduled task named ChromeUpdateCoreTaskMachineKOR to run the script every 30 minutes and fetches additional PowerShell payloads from Dropbox before deleting them. The report publishes hashes for both the ZIP and LNK, including SHA-256 44ff60d352169f280801cf2075295aab0a6151ff8f77b66d16c82776efce7fea, useful for detecting invoice themed Kimsuky LNK delivery.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 44ff60d352169f280801cf2075295aa… 2024-08-26 2025-02-13
HASH 3d3cc980ccf97cde5f3272fdc4c8856… 2024-08-26 2024-08-26
HASH 4ac2192b01fce9e793f544d09877d16b 2024-08-26 2024-08-26
HASH 9e6e4ecaea18171e2266899f1bffda5… 2024-08-26 2024-08-26
HASH d83f47dfe20c38ccec3b9869f644fd4… 2024-08-26 2024-08-26
HASH 09b1213c8a336541a4849d65b937293f 2024-08-26 2024-08-26
URL https://dl.dropboxusercontent.c… 2024-08-26 2024-08-26
URL https://dl.dropboxusercontent.c… 2024-08-26 2024-08-26

Related Actors

Related Reports

« Back