김수키(Kimsuky) 에서 만든 악성코드-Consent Form_Princeton Study.vbs(2023.8.14)

2023-08-26 Sakai Malware created by Kimsuky - Consent Form_Princeton Study.vbs (2023.8.14)

https://wezard4u.tistory.com/6562

Thumbnail for 김수키(Kimsuky) 에서 만든 악성코드-Consent Form_Princeton Study.vbs(2023.8.14)

The Korean analysis attributes a VBS malware sample named Consent Form_Princeton Study.vbs to Kimsuky and documents hashes for the script. The malware opens a Princeton-themed Google Drive lure while collecting battery and process information, checking for curl, and contacting grekop.online infrastructure. Its script manipulates browser and mail shortcuts, downloads a follow-on video.vbs payload to C:\Users\Public\Videos, establishes persistence through the HKCU Command Processor AutoRun registry value, and POSTs collected status data to the C2 endpoint. The excerpt shows the lure content was only social-engineering cover for a Windows script chain rather than the substance of the malware report.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ca8728ce8f77cfc804f9ce343de9c9ee 2023-08-26 2023-08-26
HASH 1af5d54ed7dc4e872684461a75f0cc2… 2023-08-26 2023-08-26
HASH 470027cf8dd33b201b465b109a9876d… 2023-08-26 2023-08-26
URL https://grekop.online/brad/shar… 2023-08-26 2023-08-26
URL https://grekop.online/brad/ca.p… 2023-08-26 2023-08-26
URL https://grekop.online/brad/re.p… 2023-08-26 2023-08-26
DOMAIN grekop.online 2023-08-26 2023-08-26
IPv4 74.125.143.94 2023-08-26 2023-08-26
IPv4 173.194.79.94 2023-08-26 2023-08-26
IPv4 108.177.126.132 2023-08-26 2023-08-26
IPv4 34.87.124.238 2023-08-26 2023-08-26
IPv4 34.104.35.123 2023-08-26 2023-08-26
IPv4 108.177.126.139 2023-08-26 2023-08-26
IPv4 173.194.69.94 2023-08-26 2023-08-26
IPv4 142.251.31.138 2023-08-26 2023-08-26
IPv4 108.177.126.94 2023-08-26 2023-08-26
IPv4 63.250.38.85 2023-08-26 2023-08-26
IPv4 108.177.119.95 2023-08-26 2023-08-26
IPv4 108.177.96.138 2023-08-26 2023-08-26
IPv4 192.178.27.195 2023-08-26 2023-08-26
IPv4 108.177.119.102 2023-08-26 2023-08-26
IPv4 104.18.14.101 2023-08-26 2023-08-26
IPv4 108.177.126.95 2023-08-26 2023-08-26
IPv4 192.178.49.195 2023-08-26 2023-08-26
IPv4 108.177.127.84 2023-08-26 2023-08-26
IPv4 104.18.15.101 2023-08-26 2023-08-26
IPv4 108.177.127.95 2023-08-26 2023-08-26
IPv4 173.194.79.95 2023-08-26 2023-08-26

Related Actors

Related Reports

« Back