김수키(Kimsuky) 에서 만든 거래명세서로 위장한 악성코드-거래명세서(2024,10,02)

2025-02-07 Sakai Malware Created by Kimsuky Disguised as a Transaction Statement - Transaction Statement (2024.10.02)

https://wezard4u.tistory.com/429399

Thumbnail for 김수키(Kimsuky) 에서 만든 거래명세서로 위장한 악성코드-거래명세서(2024,10,02)

The excerpt analyzes a Kimsuky-linked LNK file disguised as a transaction statement Excel spreadsheet. The shortcut contains Base64-encoded PowerShell that downloads and executes Dropbox-hosted payloads, writes scripts such as chrome.ps1 and system_first.ps1 under user profile locations, and removes temporary files after execution. Persistence is established through a hidden scheduled task named ChromeUpdateTaskMachine that runs PowerShell with execution-policy bypass five minutes after infection and then every 30 minutes. The body includes hashes for the LNK and suggests the lure may relate to small business or defense-sector targeting, but that target assessment is presented as the author’s suspicion rather than confirmed attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH acbc775087da23725c3d783311d5f50… 2025-02-07 2025-02-13
HASH 8b6bf5f4ec7045386ee8a0335b7ab70… 2025-02-07 2025-02-07
HASH cdb9a352597f10b8539d61c4b7f4d64c 2025-02-07 2025-02-07
URL https://dl.dropboxusercontent.c… 2025-02-07 2025-02-07

Related Actors

Related Reports

« Back