김수키(Kimsuky) 에서 만든 거래명세서로 위장한 악성코드-거래명세서(2024,10,02)
2025-02-07 • Sakai • Malware Created by Kimsuky Disguised as a Transaction Statement - Transaction Statement (2024.10.02) •
The excerpt analyzes a Kimsuky-linked LNK file disguised as a transaction statement Excel spreadsheet. The shortcut contains Base64-encoded PowerShell that downloads and executes Dropbox-hosted payloads, writes scripts such as chrome.ps1 and system_first.ps1 under user profile locations, and removes temporary files after execution. Persistence is established through a hidden scheduled task named ChromeUpdateTaskMachine that runs PowerShell with execution-policy bypass five minutes after infection and then every 30 minutes. The body includes hashes for the LNK and suggests the lure may relate to small business or defense-sector targeting, but that target assessment is presented as the author’s suspicion rather than confirmed attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | acbc775087da23725c3d783311d5f50… | 2025-02-07 | 2025-02-13 |
| HASH | 8b6bf5f4ec7045386ee8a0335b7ab70… | 2025-02-07 | 2025-02-07 |
| HASH | cdb9a352597f10b8539d61c4b7f4d64c | 2025-02-07 | 2025-02-07 |
| URL | https://dl.dropboxusercontent.c… | 2025-02-07 | 2025-02-07 |