김수키(Kimsuky) 에서 만든 매크로 악성코드-document.doc (copy).doc(2023.6.12)

2023-06-14 Sakai Macro malware created by Kimsuky - document.doc (copy).doc (2023.6.12)

https://wezard4u.tistory.com/6474

Thumbnail for 김수키(Kimsuky) 에서 만든 매크로 악성코드-document.doc (copy).doc(2023.6.12)

The source analyzes a Kimsuky-attributed malicious Word document named “document.doc (copy).doc” that used macro execution to run VBScript through wscript.exe. The lure content referenced South Korean politics and North Korea policy topics, suggesting targeting of journalists, policymakers, or organizations working on inter-Korean issues. Execution created an Office version.xml script under the user profile, which used MSXML2.ServerXMLHTTP to request and execute code from a compromised Korean-hosted C2 path at miracle.designsoup.co.kr. The report provides file hashes for the document and walks through the obfuscated macro logic used to build the remote URL and persistence path.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 121.78.88.79 2021-07-26 2023-11-01
HASH eabac2151828caacfa7c253d84a7b891 2023-06-14 2023-06-14
HASH 107f319f6a0f9cfc054aa725553a045… 2023-06-14 2023-06-14
HASH 20695355bf0d88a3f81b8adf45c5f0b… 2023-06-14 2023-06-14
DOMAIN e.de 2023-06-14 2023-06-14
IPv4 8.238.42.126 2023-06-14 2023-06-14
URL http://miracle.designsoup.co.kr… 2021-07-26 2023-06-14
DOMAIN miracle.designsoup.co.kr 2021-07-26 2023-06-14

Related Actors

Related Reports

« Back