김수키(Kimsuky) 가상화폐(암호 화폐)로 위장한 트레이딩 스파르타코스 강의안-100불남(2차).pdf(2024.1.22)
2024-03-28 • Sakai • Kimsuky Malware Disguised as a Cryptocurrency Trading Spartacus Lecture Material - 100-Dollar Man (Part 2).pdf (2024.1.22) •
The source analyzes a Kimsuky-attributed malware case disguised as a cryptocurrency trading lecture PDF lure. The lure is delivered through a shortcut-style infection chain rather than a benign PDF-only document, and antivirus detections identify the artifact as LNK-based malware. The report lists multiple security-engine detections for Trojan, Powecod, Boxter, and suspicious LNK behavior, supporting its handling as a malicious sample rather than publisher noise. Defenders should review shortcut-file execution, script runner behavior, and cryptocurrency-themed social-engineering lures linked to Kimsuky activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://api.dropboxapi.com/oaut… | 2023-12-29 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2020-03-25 | 2025-09-03 |
| HASH | fcdcc6c56ae43f7a78413cc5204e9314 | 2024-01-30 | 2024-04-17 |
| DOMAIN | gbionet.com | 2024-01-30 | 2024-04-17 |
| URL | https://api.dropboxapi.com/oaut… | 2024-03-28 | 2024-04-03 |
| HASH | d2fca321091b4914b2ab813b4b1b83b… | 2024-03-28 | 2024-03-28 |
| URL | http://gbionet.com// | 2024-03-28 | 2024-03-28 |
| URL | https://content.dropboxapi.com | 2024-03-28 | 2024-03-28 |
| HASH | befa4094eb7ceb31be76ec98b11353b… | 2024-01-30 | 2024-03-28 |
| URL | https://hyojadong.kr/js/slick/d… | 2024-01-30 | 2024-03-28 |
| DOMAIN | hyojadong.kr | 2024-01-30 | 2024-03-28 |