김수키(Kimsuky) 가 만든 악성코드-북의 핵위협 양상과 한국의 대응방향.chm(2023.9.18)

2023-09-23 Sakai Malicious code created by Kimsuky - North Korea's nuclear threat and Korea's response direction.chm (2023.9.18)

https://wezard4u.tistory.com/6604

Thumbnail for 김수키(Kimsuky) 가 만든 악성코드-북의 핵위협 양상과 한국의 대응방향.chm(2023.9.18)

Kimsuky is reported as using a CHM lure titled around North Korea's nuclear threat and South Korea's response, presented as if it were written by a North Korea strategy researcher. The CHM contains an ActiveX shortcut object that runs cmd commands to write Base64 data under the user's Links folder, decode it with certutil into a VBS file, and add a Run key for persistence. The dropped VBS uses Microsoft.XMLHTTP to fetch and execute code from 00701111.000webhostapp.com/wp-extra/show.php?query=50. The source includes hashes for both the CHM and VBS and assesses the targeting as likely aimed at people involved in North Korea-related work.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://00701111.000webhostapp.c… 2023-09-23 2024-12-27
DOMAIN 00701111.000webhostapp.com 2023-09-23 2024-12-27
HASH b5224224fdbabdea53a91a96e9f816c… 2023-09-23 2024-03-20
HASH 364d4fdf430477222fe854b3cd5b6d40 2023-09-23 2024-03-20
HASH c62677543eeb50e0def44fc75009a77… 2023-09-23 2024-03-20
HASH bd7527b2809ea227ff5f4107d3aecfd… 2023-09-23 2023-09-23
HASH 59a0b32c22c79e7e48614add0e5cdf8… 2023-09-23 2023-09-23
HASH 149a6639da7897a928b6f96c0f80612d 2023-09-23 2023-09-23

Related Actors

Related Reports

« Back