김수키(Kimsuky) 에서 만든 악성코드-Consent Form_Princeton Study.vbs(2023.8.14)
2023-08-26 • Sakai • Malware created by Kimsuky - Consent Form_Princeton Study.vbs (2023.8.14) •
The Korean analysis attributes a VBS malware sample named Consent Form_Princeton Study.vbs to Kimsuky and documents hashes for the script. The malware opens a Princeton-themed Google Drive lure while collecting battery and process information, checking for curl, and contacting grekop.online infrastructure. Its script manipulates browser and mail shortcuts, downloads a follow-on video.vbs payload to C:\Users\Public\Videos, establishes persistence through the HKCU Command Processor AutoRun registry value, and POSTs collected status data to the C2 endpoint. The excerpt shows the lure content was only social-engineering cover for a Windows script chain rather than the substance of the malware report.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ca8728ce8f77cfc804f9ce343de9c9ee | 2023-08-26 | 2023-08-26 |
| HASH | 1af5d54ed7dc4e872684461a75f0cc2… | 2023-08-26 | 2023-08-26 |
| HASH | 470027cf8dd33b201b465b109a9876d… | 2023-08-26 | 2023-08-26 |
| URL | https://grekop.online/brad/shar… | 2023-08-26 | 2023-08-26 |
| URL | https://grekop.online/brad/ca.p… | 2023-08-26 | 2023-08-26 |
| URL | https://grekop.online/brad/re.p… | 2023-08-26 | 2023-08-26 |
| DOMAIN | grekop.online | 2023-08-26 | 2023-08-26 |
| IPv4 | 74.125.143.94 | 2023-08-26 | 2023-08-26 |
| IPv4 | 173.194.79.94 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.126.132 | 2023-08-26 | 2023-08-26 |
| IPv4 | 34.87.124.238 | 2023-08-26 | 2023-08-26 |
| IPv4 | 34.104.35.123 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.126.139 | 2023-08-26 | 2023-08-26 |
| IPv4 | 173.194.69.94 | 2023-08-26 | 2023-08-26 |
| IPv4 | 142.251.31.138 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.126.94 | 2023-08-26 | 2023-08-26 |
| IPv4 | 63.250.38.85 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.119.95 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.96.138 | 2023-08-26 | 2023-08-26 |
| IPv4 | 192.178.27.195 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.119.102 | 2023-08-26 | 2023-08-26 |
| IPv4 | 104.18.14.101 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.126.95 | 2023-08-26 | 2023-08-26 |
| IPv4 | 192.178.49.195 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.127.84 | 2023-08-26 | 2023-08-26 |
| IPv4 | 104.18.15.101 | 2023-08-26 | 2023-08-26 |
| IPv4 | 108.177.127.95 | 2023-08-26 | 2023-08-26 |
| IPv4 | 173.194.79.95 | 2023-08-26 | 2023-08-26 |