문서 뷰어로 위장한 악성 배치 파일(*.bat) 유포 중(Kimsuky)
2023-06-30 • Ahnlab • Distributing malicious batch files (*.bat) disguised as document viewers (Kimsuky) •
AhnLab reports that malware assessed as Kimsuky activity was distributed as batch files disguised as document viewers, likely via email, with decoy Google Drive/Docs documents about military and Korean unification topics. The BAT file used WMIC to check installed security products and downloaded different scripts from joongang[.]site depending on Kaspersky, Avast, AhnLab V3, or other process matches. Follow-on components replaced Word's Normal.dotm, registered VBS persistence through the registry, startup folder, or a scheduled task, and modified browser/email shortcuts so user launches could execute attacker-controlled commands such as mshta. The scripts also collected host details including battery and process information and sent them to joongang[.]site, while AhnLab listed related BAT/VBS detections and representative infrastructure such as joongang[.]site and namsouth[.]com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | namsouth.com | 2023-06-30 | 2024-02-28 |
| HASH | 8536d838dcdd026c57187ec2c3aec0f6 | 2023-06-30 | 2023-07-10 |
| HASH | 00119ed01689e76cb7f33646693ecd6a | 2023-06-30 | 2023-07-10 |
| HASH | 7d79901b01075e29d8505e72d225ff52 | 2023-06-30 | 2023-07-10 |
| HASH | a7ac7d100184078c2aa5645552794c19 | 2023-06-30 | 2023-07-10 |
| URL | http://joongang.site/pprb/sec/c… | 2023-06-30 | 2023-07-10 |
| URL | http://joongang.site/pprb/sec/c… | 2023-06-30 | 2023-07-10 |
| URL | http://namsouth.com/gopprb/OpOp… | 2023-06-30 | 2023-07-10 |
| URL | http://joongang.site/docx/ | 2023-06-30 | 2023-07-10 |
| URL | https://joongang.site/pprb/sec/… | 2023-06-30 | 2023-07-10 |
| URL | http://joongang.site/pprb/sec/c… | 2023-06-30 | 2023-07-10 |
| URL | http://joongang.site/pprb/sec/ | 2023-06-30 | 2023-07-10 |
| URL | http://joongang.site/pprb/sec/d… | 2023-06-30 | 2023-07-10 |
| URL | https://joongang.site/pprb/sec/… | 2023-06-30 | 2023-07-10 |
| URL | http://joongang.site/doc/ | 2023-06-30 | 2023-07-10 |
| URL | https://joongang.site/pprb/sec/… | 2023-06-30 | 2023-07-10 |
| URL | http://staradvertiser.store/sig… | 2023-06-30 | 2023-07-10 |
| URL | https://joongang.site/pprb/sec/… | 2023-06-30 | 2023-07-10 |
| URL | https://joongang.site/pprb/sec/… | 2023-06-30 | 2023-07-10 |
| DOMAIN | staradvertiser.store | 2023-06-30 | 2023-07-10 |
| DOMAIN | joongang.site | 2023-06-30 | 2023-07-10 |