김수키(Kimsuky) 코인 선물 트레이딩으로 위장 하고 있는 악성코드-코인 선물 트레이딩 비법서, 수익률 증폭의 핵심 원리.pdf.lnk(2024.10.14)
2024-10-14 • Sakai • Malware by Kimsuky Disguised as Coin Futures Trading - Coin Futures Trading Guide, Core Principles for Amplifying Returns.pdf.lnk (2024.10.14) •
A Kimsuky-linked Windows shortcut sample is disguised as a PDF guide about coin futures trading and is described as targeting people interested in cryptocurrency or futures trading. The LNK launches hidden, non-interactive PowerShell, builds a Dropboxusercontent URL, downloads an encrypted ad_ps.bin payload, decrypts it with a hardcoded password, and executes the resulting script. Follow-on PowerShell collects host details such as IP address, boot time, OS information, computer type, antivirus products, install date, and running processes. The collected data is written to a timestamped text file, uploaded through the Dropbox API, and then removed locally, making the sample useful for tracking Kimsuky-style cloud-service abuse and information theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4e317495e0c2ae3e46a9f7a810184b30 | 2024-10-14 | 2024-10-14 |
| HASH | af0b9aea91b2ea6567fbd4ba19839b4… | 2024-10-14 | 2024-10-14 |
| HASH | d47fe15d4f1176e1952d11b2cfeaebb… | 2024-10-14 | 2024-10-14 |
| DOMAIN | ontent.com | 2024-10-14 | 2024-10-14 |
| IPv4 | 6.6.4.1 | 2024-10-08 | 2024-10-14 |