북한 김수키(Kimsuky)양도소득 과세표준 신고 및 납부계산서 로 위장한 악성코드-out.lnk(2024.11.26)

2024-11-27 Sakai Malware by North Korea's Kimsuky Disguised as a Capital Gains Tax Base Return and Payment Calculation Form - out.lnk (2024.11.26)

https://wezard4u.tistory.com/429342

Thumbnail for 북한 김수키(Kimsuky)양도소득 과세표준 신고 및 납부계산서 로 위장한 악성코드-out.lnk(2024.11.26)

Kimsuky is linked to a Windows LNK payload disguised as a Korean capital gains tax base report and payment calculation PDF. The shortcut launches PowerShell, decodes embedded script content, downloads a decoy PDF and additional Dropbox-hosted scripts, and registers a hidden scheduled task named ChromeUpdateTaskMachineKOR to rerun chrome.ps1 every 30 minutes. Follow-on PowerShell collects host information such as IP address, OS details, boot time, installed antivirus products, and running processes, then uploads the results to Dropbox using OAuth and the content upload API. The excerpt provides the LNK hashes, Dropbox URLs and API endpoints, local AppData and Temp file paths, and the scheduled-task name for detection and response.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.dropboxapi.com/oaut… 2023-12-29 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
URL https://dl.dropboxusercontent.c… 2024-11-27 2025-02-13
HASH f5740e4027ad48231f199b18b8ae15a… 2024-11-27 2024-11-27
HASH adcd2bcd43a6f495facfe31e71d4e2b8 2024-11-27 2024-11-27
HASH 4bdbf8733e178d50f1763d5999b58bb… 2024-11-27 2024-11-27
URL https://dl.dropboxusercontent.c… 2024-11-27 2024-11-27
URL https://dl.dropboxusercontent.c… 2024-11-27 2024-11-27
URL https://dl.dropboxusercontent.c… 2024-11-27 2024-11-27
URL https://dl.dropboxusercontent.c… 2024-11-27 2024-11-27

Related Actors

Related Reports

« Back