김수키(Kimsuky) 에서 제작한 악성코드-현대 데이터 복구 및 절차 수립
2025-09-11 • Sakai • Malware Created by Kimsuky - Hyundai Data Recovery and Procedure Establishment •
The Korean analysis attributes a large malicious LNK file themed around Hyundai data recovery and procedure establishment to Kimsuky, while noting uncertainty about how the lure content was obtained. The shortcut contains PowerShell that searches for an oversized LNK, extracts an embedded decoy PDF, XOR-decrypts an executable and manifest, and writes them to the hidden system-marked directory C:\tempcaches. Persistence is created with two scheduled tasks: one runs C:\tempcaches\ms.exe every 10 minutes and another invokes wscript against c:\tempcaches\cache.vbs every 11 minutes, after which the original LNK is removed. The analysis provides file hashes, dropped paths, task names, and relevant Windows logging sources, making the sample useful for detecting Kimsuky-style LNK execution, payload extraction, and scheduled-task persistence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.32.133.19 | 2025-09-08 | 2025-09-17 |
| HASH | e44f8592680fd14373a51b9667c6e6e… | 2025-09-11 | 2025-09-11 |
| HASH | 75712ce08f5c6c78b3ba8ff94d8ee264 | 2025-09-11 | 2025-09-11 |
| HASH | 553616ae94ec7e7fb97f886bb5c4e66… | 2025-09-11 | 2025-09-11 |