김수키(Kimsuky) 에서 만든 매크로 악성코드-document.doc (copy).doc(2023.6.12)
2023-06-14 • Sakai • Macro malware created by Kimsuky - document.doc (copy).doc (2023.6.12) •
The source analyzes a Kimsuky-attributed malicious Word document named “document.doc (copy).doc” that used macro execution to run VBScript through wscript.exe. The lure content referenced South Korean politics and North Korea policy topics, suggesting targeting of journalists, policymakers, or organizations working on inter-Korean issues. Execution created an Office version.xml script under the user profile, which used MSXML2.ServerXMLHTTP to request and execute code from a compromised Korean-hosted C2 path at miracle.designsoup.co.kr. The report provides file hashes for the document and walks through the obfuscated macro logic used to build the remote URL and persistence path.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 121.78.88.79 | 2021-07-26 | 2023-11-01 |
| HASH | eabac2151828caacfa7c253d84a7b891 | 2023-06-14 | 2023-06-14 |
| HASH | 107f319f6a0f9cfc054aa725553a045… | 2023-06-14 | 2023-06-14 |
| HASH | 20695355bf0d88a3f81b8adf45c5f0b… | 2023-06-14 | 2023-06-14 |
| DOMAIN | e.de | 2023-06-14 | 2023-06-14 |
| IPv4 | 8.238.42.126 | 2023-06-14 | 2023-06-14 |
| URL | http://miracle.designsoup.co.kr… | 2021-07-26 | 2023-06-14 |
| DOMAIN | miracle.designsoup.co.kr | 2021-07-26 | 2023-06-14 |