김수키(Kimsuky)에서 만든 항공우주공학과 관련자 타겟팅 악성코드-강의의뢰서(2024.8.29)
2024-08-29 • Sakai • Malware Created by Kimsuky Targeting People Related to Aerospace Engineering - Lecture Request Form (2024.8.29) •
A Korean malware analysis attributes an MSC sample to Kimsuky activity targeting aerospace-related personnel with a lecture request lure impersonating a KAIST aerospace professor's speaking engagement. The MSC launches cmd.exe in a minimized window, downloads a decoy Word document and additional files from rem.zoom-meeting.kro.kr under the 0829_pprb path, writes a payload as %appdata%\pest.exe, and creates a scheduled task named TemporaryClearStatesesf to run it every 58 minutes. The lure document describes a Seoul hotel lecture on the space economy, supporting the author's assessment that the operation was aimed at aerospace technology or academic contacts. The source provides hashes for the MSC sample, including SHA-256 8028b918d06cf3635e7e77d29cb0a4622d8cf4ee30881fb297435f7328ff45e4, and notes antivirus detections as Kimsuky-themed MSC malware.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rem.zoom-meeting.kro.kr | 2024-08-29 | 2025-03-07 |
| HASH | 8028b918d06cf3635e7e77d29cb0a46… | 2024-08-29 | 2024-11-20 |
| HASH | ef8947d291107256cb5883ac3bc163d0 | 2024-08-29 | 2024-10-04 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-08-29 | 2024-09-02 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-08-29 | 2024-09-02 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-08-29 | 2024-09-02 |
| DOMAIN | g.kro.kr | 2024-08-29 | 2024-09-02 |
| HASH | cf8555a2d9fc8081ba8c8e29f7905dd… | 2024-08-29 | 2024-08-29 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-08-29 | 2024-08-29 |