대북 관계자를 목표를 하고 있는 김수키(Kimsuky) 만든 악성코드-북한인권단체 활동의 어려움과 활성화 방안 이광백대표.chm(2023.5.9)

2023-11-01 Sakai Malicious code created by Kimsuky targeting North Korean officials - Difficulties and ways to revitalize activities of North Korean human rights groups Representative Lee Gwang-baek.chm (May 9, 2023)

https://wezard4u.tistory.com/6645

Thumbnail for 대북 관계자를 목표를 하고 있는 김수키(Kimsuky) 만든 악성코드-북한인권단체 활동의 어려움과 활성화 방안 이광백대표.chm(2023.5.9)

The Korean analysis describes a Kimsuky-linked CHM malware lure targeting people who work on North Korea issues, using a document titled as a DailyNK representative's discussion of North Korean human rights group activity. The lure arrived in a password-protected ZIP and displayed benign Korean human rights content, but the CHM page embedded a base64 encoded command that wrote mini.dat under the user profile, decoded it with certutil into mini.vbs, and registered it under HKCU\Software\Microsoft\Windows\CurrentVersion\Run for logon persistence. The decoded VBScript used Microsoft.XMLHTTP to fetch and execute code from hxxp://file.com-port.space/indeed/show.php?query=50. The source provides hashes for the CHM and generated mini.vbs plus observed network endpoints and VirusTotal detections.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bbcfcc719190f0a2c687778d5d2fd5c… 2023-11-01 2023-11-01
HASH c48221dba16382aeff0ac35aa0b93682 2023-11-01 2023-11-01
HASH 76b2f8df4578d65d5b6d57af8784584… 2023-11-01 2023-11-01
HASH 002fd493096214a9a44d82acb7f1ac30 2023-11-01 2023-11-01
HASH 128fac6c2a68dd844fe51a86308a381… 2023-11-01 2023-11-01
URL http://file.com-port.space/inde… 2023-11-01 2023-11-01
DOMAIN file.com-port.space 2023-11-01 2023-11-01
IPv4 8.252.193.254 2023-11-01 2023-11-01
IPv4 8.248.153.254 2023-11-01 2023-11-01
IPv4 157.7.184.26 2023-11-01 2023-11-01
IPv4 209.197.3.8 2023-11-01 2023-11-01
HASH 49c70c292a634e822300c57305698b5… 2023-05-23 2023-11-01

Related Actors

Related Reports

« Back