김수키(Kimsuky) 외교광장.ps1 악성코드 분석 및 보안 수칙 ESET 탐지 PowerShell/Kimsuky.AX
2025-09-03 • Sakai • Kimsuky Diplomatic Plaza.ps1 Malware Analysis and Security Guidelines, ESET Detection PowerShell/Kimsuky.AX •
A PowerShell script identified in the source as ESET PowerShell/Kimsuky.AX targeted a South Korean foreign-policy organization and collected host reconnaissance data before staging additional payloads. The script gathered running processes, OS version, public IP address, and installed antivirus product details, wrote them to a temporary file, uploaded the data to Dropbox through embedded OAuth credentials, and then deleted the local file. It attempted to download a Dropbox-hosted batch file to C:\Users\Public\Music\po.bat, rename the remote file after retrieval, and execute the batch silently through cmd.exe. The follow-on batch logic downloaded files from koreadiplomacyplaza.kro.kr, copied an executable, manifest, and PowerShell script into C:\Users\Public\Videos, and created a scheduled task named Transt_Feed_Synchronization-{0DDC1BD9-E733-425C-B92B-ABAC149AB11264} for persistence. The activity matters because it combines targeted South Korean political and foreign-policy victimology with cloud-based exfiltration, Korea-themed infrastructure, and scheduled-task persistence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 208.67.222.220 | 2025-09-03 | 2026-03-17 |
| HASH | 3f0a89e8b1d4ab1b901c3bce93a8eae… | 2025-09-03 | 2025-09-03 |
| HASH | 89a6d3392668ba1b765a5ebcc8ac504… | 2025-09-03 | 2025-09-03 |
| HASH | 8ef331da6a71931c8843488c6d13a1a2 | 2025-09-03 | 2025-09-03 |
| URL | https://koreadiplomacyplaza.kro… | 2025-09-03 | 2025-09-03 |
| URL | https://koreadiplomacyplaza.kro… | 2025-09-03 | 2025-09-03 |
| URL | https://koreadiplomacyplaza.kro… | 2025-09-03 | 2025-09-03 |
| URL | https://koreadiplomacyplaza.kro… | 2025-09-03 | 2025-09-03 |
| URL | https://api.dropboxapi.com/2/fi… | 2025-09-03 | 2025-09-03 |
| DOMAIN | oxapi.com | 2025-09-03 | 2025-09-03 |
| DOMAIN | koreadiplomacyplaza.kro.kr | 2025-09-03 | 2025-09-03 |
| URL | https://api.dropboxapi.com/oaut… | 2023-12-29 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2020-03-25 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2018-09-21 | 2025-09-03 |