김수키(Kimsuky) 보조금신청 관련문의건 으로 위장 하는 악성코드(2024.9.23)

2024-09-26 Sakai Kimsuky malware disguised as a subsidy application inquiry

http://wezard4u.tistory.com/429286

Thumbnail for 김수키(Kimsuky) 보조금신청 관련문의건 으로 위장 하는 악성코드(2024.9.23)

Kimsuky is linked in the excerpt to a malicious LNK file disguised as a subsidy-application inquiry document, with SHA-256 24a0124e2e38407f2062dc2bfb0bd474413a10d80ef8e1913ecfa699d962229f. The LNK invokes mshta.exe and obfuscated script content to run PowerShell with execution-policy bypass, connect to 64.49.14.181 on port 8014, and receive Base64-encoded data. The decoded content is written as c:\programdata\t.zip, extracted into ProgramData, and followed by execution of s.vbs and a service-control command intended to continue the chain. The author notes the same C2 infrastructure appeared in the earlier Upbit-themed sample and that, at the time of testing, only t.zip was created because the server no longer completed the next stage.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ck.org 2024-09-26 2024-10-01
HASH 1f29ccc30a6d053fcbc5210d921ac721 2024-09-26 2024-09-26
HASH 35b7c9abc46750e9c1f672086427326… 2024-09-26 2024-09-26
HASH 24a0124e2e38407f2062dc2bfb0bd47… 2024-09-26 2024-09-26
IPv4 64.49.14.181 2024-09-17 2024-09-26

Related Actors

Related Reports

« Back