김수키(Kimsuky) 외교광장.ps1 악성코드 분석 및 보안 수칙 ESET 탐지 PowerShell/Kimsuky.AX

2025-09-03 Sakai Kimsuky Diplomatic Plaza.ps1 Malware Analysis and Security Guidelines, ESET Detection PowerShell/Kimsuky.AX

https://wezard4u.tistory.com/429586

Thumbnail for 김수키(Kimsuky) 외교광장.ps1 악성코드 분석 및 보안 수칙 ESET 탐지 PowerShell/Kimsuky.AX

A PowerShell script identified in the source as ESET PowerShell/Kimsuky.AX targeted a South Korean foreign-policy organization and collected host reconnaissance data before staging additional payloads. The script gathered running processes, OS version, public IP address, and installed antivirus product details, wrote them to a temporary file, uploaded the data to Dropbox through embedded OAuth credentials, and then deleted the local file. It attempted to download a Dropbox-hosted batch file to C:\Users\Public\Music\po.bat, rename the remote file after retrieval, and execute the batch silently through cmd.exe. The follow-on batch logic downloaded files from koreadiplomacyplaza.kro.kr, copied an executable, manifest, and PowerShell script into C:\Users\Public\Videos, and created a scheduled task named Transt_Feed_Synchronization-{0DDC1BD9-E733-425C-B92B-ABAC149AB11264} for persistence. The activity matters because it combines targeted South Korean political and foreign-policy victimology with cloud-based exfiltration, Korea-themed infrastructure, and scheduled-task persistence.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 208.67.222.220 2025-09-03 2026-03-17
HASH 3f0a89e8b1d4ab1b901c3bce93a8eae… 2025-09-03 2025-09-03
HASH 89a6d3392668ba1b765a5ebcc8ac504… 2025-09-03 2025-09-03
HASH 8ef331da6a71931c8843488c6d13a1a2 2025-09-03 2025-09-03
URL https://koreadiplomacyplaza.kro… 2025-09-03 2025-09-03
URL https://koreadiplomacyplaza.kro… 2025-09-03 2025-09-03
URL https://koreadiplomacyplaza.kro… 2025-09-03 2025-09-03
URL https://koreadiplomacyplaza.kro… 2025-09-03 2025-09-03
URL https://api.dropboxapi.com/2/fi… 2025-09-03 2025-09-03
DOMAIN oxapi.com 2025-09-03 2025-09-03
DOMAIN koreadiplomacyplaza.kro.kr 2025-09-03 2025-09-03
URL https://api.dropboxapi.com/oaut… 2023-12-29 2025-09-03
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03

Related Actors

Related Reports

« Back