김수키(Kimsuky)에서 만든 항공우주공학과 관련자 타겟팅 악성코드-강의의뢰서(2024.8.29)

2024-08-29 Sakai Malware Created by Kimsuky Targeting People Related to Aerospace Engineering - Lecture Request Form (2024.8.29)

https://wezard4u.tistory.com/429266

Thumbnail for 김수키(Kimsuky)에서 만든 항공우주공학과 관련자 타겟팅 악성코드-강의의뢰서(2024.8.29)

A Korean malware analysis attributes an MSC sample to Kimsuky activity targeting aerospace-related personnel with a lecture request lure impersonating a KAIST aerospace professor's speaking engagement. The MSC launches cmd.exe in a minimized window, downloads a decoy Word document and additional files from rem.zoom-meeting.kro.kr under the 0829_pprb path, writes a payload as %appdata%\pest.exe, and creates a scheduled task named TemporaryClearStatesesf to run it every 58 minutes. The lure document describes a Seoul hotel lecture on the space economy, supporting the author's assessment that the operation was aimed at aerospace technology or academic contacts. The source provides hashes for the MSC sample, including SHA-256 8028b918d06cf3635e7e77d29cb0a4622d8cf4ee30881fb297435f7328ff45e4, and notes antivirus detections as Kimsuky-themed MSC malware.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN rem.zoom-meeting.kro.kr 2024-08-29 2025-03-07
HASH 8028b918d06cf3635e7e77d29cb0a46… 2024-08-29 2024-11-20
HASH ef8947d291107256cb5883ac3bc163d0 2024-08-29 2024-10-04
URL http://rem.zoom-meeting.kro.kr/… 2024-08-29 2024-09-02
URL http://rem.zoom-meeting.kro.kr/… 2024-08-29 2024-09-02
URL http://rem.zoom-meeting.kro.kr/… 2024-08-29 2024-09-02
DOMAIN g.kro.kr 2024-08-29 2024-09-02
HASH cf8555a2d9fc8081ba8c8e29f7905dd… 2024-08-29 2024-08-29
URL http://rem.zoom-meeting.kro.kr/… 2024-08-29 2024-08-29

Related Actors

Related Reports

« Back