북한 김수키(Kimsuky)양도소득 과세표준 신고 및 납부계산서 로 위장한 악성코드-out.lnk(2024.11.26)
2024-11-27 • Sakai • Malware by North Korea's Kimsuky Disguised as a Capital Gains Tax Base Return and Payment Calculation Form - out.lnk (2024.11.26) •
Kimsuky is linked to a Windows LNK payload disguised as a Korean capital gains tax base report and payment calculation PDF. The shortcut launches PowerShell, decodes embedded script content, downloads a decoy PDF and additional Dropbox-hosted scripts, and registers a hidden scheduled task named ChromeUpdateTaskMachineKOR to rerun chrome.ps1 every 30 minutes. Follow-on PowerShell collects host information such as IP address, OS details, boot time, installed antivirus products, and running processes, then uploads the results to Dropbox using OAuth and the content upload API. The excerpt provides the LNK hashes, Dropbox URLs and API endpoints, local AppData and Temp file paths, and the scheduled-task name for detection and response.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://api.dropboxapi.com/oaut… | 2023-12-29 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2018-09-21 | 2025-09-03 |
| URL | https://dl.dropboxusercontent.c… | 2024-11-27 | 2025-02-13 |
| HASH | f5740e4027ad48231f199b18b8ae15a… | 2024-11-27 | 2024-11-27 |
| HASH | adcd2bcd43a6f495facfe31e71d4e2b8 | 2024-11-27 | 2024-11-27 |
| HASH | 4bdbf8733e178d50f1763d5999b58bb… | 2024-11-27 | 2024-11-27 |
| URL | https://dl.dropboxusercontent.c… | 2024-11-27 | 2024-11-27 |
| URL | https://dl.dropboxusercontent.c… | 2024-11-27 | 2024-11-27 |
| URL | https://dl.dropboxusercontent.c… | 2024-11-27 | 2024-11-27 |
| URL | https://dl.dropboxusercontent.c… | 2024-11-27 | 2024-11-27 |