김수키(Kimsuky) 가상화폐(암호 화폐)로 위장한 트레이딩 스파르타코스 강의안-100불남(2차).pdf(2024.1.22)

2024-03-28 Sakai Kimsuky Malware Disguised as a Cryptocurrency Trading Spartacus Lecture Material - 100-Dollar Man (Part 2).pdf (2024.1.22)

https://wezard4u.tistory.com/6769

Thumbnail for 김수키(Kimsuky) 가상화폐(암호 화폐)로 위장한 트레이딩 스파르타코스 강의안-100불남(2차).pdf(2024.1.22)

The source analyzes a Kimsuky-attributed malware case disguised as a cryptocurrency trading lecture PDF lure. The lure is delivered through a shortcut-style infection chain rather than a benign PDF-only document, and antivirus detections identify the artifact as LNK-based malware. The report lists multiple security-engine detections for Trojan, Powecod, Boxter, and suspicious LNK behavior, supporting its handling as a malicious sample rather than publisher noise. Defenders should review shortcut-file execution, script runner behavior, and cryptocurrency-themed social-engineering lures linked to Kimsuky activity.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.dropboxapi.com/oaut… 2023-12-29 2025-09-03
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
HASH fcdcc6c56ae43f7a78413cc5204e9314 2024-01-30 2024-04-17
DOMAIN gbionet.com 2024-01-30 2024-04-17
URL https://api.dropboxapi.com/oaut… 2024-03-28 2024-04-03
HASH d2fca321091b4914b2ab813b4b1b83b… 2024-03-28 2024-03-28
URL http://gbionet.com// 2024-03-28 2024-03-28
URL https://content.dropboxapi.com 2024-03-28 2024-03-28
HASH befa4094eb7ceb31be76ec98b11353b… 2024-01-30 2024-03-28
URL https://hyojadong.kr/js/slick/d… 2024-01-30 2024-03-28
DOMAIN hyojadong.kr 2024-01-30 2024-03-28

Related Actors

Related Reports

« Back