로그인 정보를 훔치는것 으로 추정 되는 북한 APT 김수키(Kimsuky)만든 악성코드-.lnk(2024.11.8)
2024-11-13 • Sakai • Malware Presumed to Steal Login Information, Created by North Korea's APT Kimsuky - .lnk (2024.11.8) •
A Korean malware write-up analyzes a Windows LNK sample attributed to Kimsuky and assessed as likely designed to steal login information. The evidence includes file hashes for the shortcut, obfuscated command-line content embedded in the LNK, and Windows shortcut metadata rather than a benign document workflow. Defenders should treat the sample as DPRK-linked credential-theft activity, pivot on the published MD5, SHA-1, and SHA-256 values, and monitor for suspicious shortcut execution chains that launch command interpreters or scripted payloads.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://partybbq.co.kr/src/bbs/… | 2024-11-13 | 2024-11-13 |
| HASH | e13ad0ebaac36ec363eba5760e69cb9… | 2024-11-08 | 2024-11-13 |
| HASH | b7de564386ab778046b1dd3ef76e4b5e | 2024-11-08 | 2024-11-13 |
| HASH | baa69876baa6861db5736c58d2eded9… | 2024-11-08 | 2024-11-13 |
| URL | http://partybbq.co.kr/src/bbs/c… | 2023-08-28 | 2024-11-13 |
| DOMAIN | partybbq.co.kr | 2023-05-24 | 2024-11-13 |