김수키(Kimsuky)에서 만든 고속국도 제29호선 세종-안성 간 건설공사 송장으로 위장 하는 악성코드-도x기업 20240610 송장.bmp.lnk(2024.7.30)
2024-08-26 • Sakai • Malware Created by Kimsuky Disguised as an Invoice for the Sejong-Anseong Construction Work on Expressway No. 29 - Do X Company 20240610 Invoice.bmp.lnk (2024.7.30) •
A Kimsuky linked archive used a highway construction invoice theme and hid an LNK file behind a BMP filename, "Do-yang Company 20240610 invoice cover.bmp.lnk". The shortcut runs hidden PowerShell, decodes a Base64 command, downloads a decoy BMP from Dropbox, and writes chrome.ps1 under AppData. It then registers a hidden scheduled task named ChromeUpdateCoreTaskMachineKOR to run the script every 30 minutes and fetches additional PowerShell payloads from Dropbox before deleting them. The report publishes hashes for both the ZIP and LNK, including SHA-256 44ff60d352169f280801cf2075295aab0a6151ff8f77b66d16c82776efce7fea, useful for detecting invoice themed Kimsuky LNK delivery.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 44ff60d352169f280801cf2075295aa… | 2024-08-26 | 2025-02-13 |
| HASH | 3d3cc980ccf97cde5f3272fdc4c8856… | 2024-08-26 | 2024-08-26 |
| HASH | 4ac2192b01fce9e793f544d09877d16b | 2024-08-26 | 2024-08-26 |
| HASH | 9e6e4ecaea18171e2266899f1bffda5… | 2024-08-26 | 2024-08-26 |
| HASH | d83f47dfe20c38ccec3b9869f644fd4… | 2024-08-26 | 2024-08-26 |
| HASH | 09b1213c8a336541a4849d65b937293f | 2024-08-26 | 2024-08-26 |
| URL | https://dl.dropboxusercontent.c… | 2024-08-26 | 2024-08-26 |
| URL | https://dl.dropboxusercontent.c… | 2024-08-26 | 2024-08-26 |