대북 관계자를 목표를 하고 있는 김수키(Kimsuky) 만든 악성코드-북한인권단체 활동의 어려움과 활성화 방안 이광백대표.chm(2023.5.9)
2023-11-01 • Sakai • Malicious code created by Kimsuky targeting North Korean officials - Difficulties and ways to revitalize activities of North Korean human rights groups Representative Lee Gwang-baek.chm (May 9, 2023) •
The Korean analysis describes a Kimsuky-linked CHM malware lure targeting people who work on North Korea issues, using a document titled as a DailyNK representative's discussion of North Korean human rights group activity. The lure arrived in a password-protected ZIP and displayed benign Korean human rights content, but the CHM page embedded a base64 encoded command that wrote mini.dat under the user profile, decoded it with certutil into mini.vbs, and registered it under HKCU\Software\Microsoft\Windows\CurrentVersion\Run for logon persistence. The decoded VBScript used Microsoft.XMLHTTP to fetch and execute code from hxxp://file.com-port.space/indeed/show.php?query=50. The source provides hashes for the CHM and generated mini.vbs plus observed network endpoints and VirusTotal detections.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | bbcfcc719190f0a2c687778d5d2fd5c… | 2023-11-01 | 2023-11-01 |
| HASH | c48221dba16382aeff0ac35aa0b93682 | 2023-11-01 | 2023-11-01 |
| HASH | 76b2f8df4578d65d5b6d57af8784584… | 2023-11-01 | 2023-11-01 |
| HASH | 002fd493096214a9a44d82acb7f1ac30 | 2023-11-01 | 2023-11-01 |
| HASH | 128fac6c2a68dd844fe51a86308a381… | 2023-11-01 | 2023-11-01 |
| URL | http://file.com-port.space/inde… | 2023-11-01 | 2023-11-01 |
| DOMAIN | file.com-port.space | 2023-11-01 | 2023-11-01 |
| IPv4 | 8.252.193.254 | 2023-11-01 | 2023-11-01 |
| IPv4 | 8.248.153.254 | 2023-11-01 | 2023-11-01 |
| IPv4 | 157.7.184.26 | 2023-11-01 | 2023-11-01 |
| IPv4 | 209.197.3.8 | 2023-11-01 | 2023-11-01 |
| HASH | 49c70c292a634e822300c57305698b5… | 2023-05-23 | 2023-11-01 |