김수키(Kimsuky) 에서 제작한 악성코드-현대 데이터 복구 및 절차 수립

2025-09-11 Sakai Malware Created by Kimsuky - Hyundai Data Recovery and Procedure Establishment

https://wezard4u.tistory.com/429595

Thumbnail for 김수키(Kimsuky) 에서 제작한 악성코드-현대 데이터 복구 및 절차 수립

The Korean analysis attributes a large malicious LNK file themed around Hyundai data recovery and procedure establishment to Kimsuky, while noting uncertainty about how the lure content was obtained. The shortcut contains PowerShell that searches for an oversized LNK, extracts an embedded decoy PDF, XOR-decrypts an executable and manifest, and writes them to the hidden system-marked directory C:\tempcaches. Persistence is created with two scheduled tasks: one runs C:\tempcaches\ms.exe every 10 minutes and another invokes wscript against c:\tempcaches\cache.vbs every 11 minutes, after which the original LNK is removed. The analysis provides file hashes, dropped paths, task names, and relevant Windows logging sources, making the sample useful for detecting Kimsuky-style LNK execution, payload extraction, and scheduled-task persistence.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.32.133.19 2025-09-08 2025-09-17
HASH e44f8592680fd14373a51b9667c6e6e… 2025-09-11 2025-09-11
HASH 75712ce08f5c6c78b3ba8ff94d8ee264 2025-09-11 2025-09-11
HASH 553616ae94ec7e7fb97f886bb5c4e66… 2025-09-11 2025-09-11

Related Actors

Related Reports

« Back