북한 김수키(Kimsuky)에서 만든 국세청 사칭 악성코드-22 귀속 부가가치세 면세사업자 사업장 현황신고(2023.4.6)

2023-05-05 Sakai Malicious code impersonating the National Tax Service created by Kimsuky in North Korea-22 Report on business status for value-added tax exempt businesses (April 6, 2023)

https://wezard4u.tistory.com/6432

Thumbnail for 북한 김수키(Kimsuky)에서 만든 국세청 사칭 악성코드-22 귀속 부가가치세 면세사업자 사업장 현황신고(2023.4.6)

The Korean analysis describes a Kimsuky-attributed campaign using a RAR archive themed as a South Korean National Tax Service notice for VAT-exempt business status reporting. Inside the archive, a very large LNK file masquerading as an HWP tax-audit notice launches hidden PowerShell that decodes embedded hexadecimal script content, extracts payload data from the oversized shortcut, writes files into public/documents paths, and starts a VBS script. The source provides hashes for the archive and LNK and places the activity in Kimsuky’s broader espionage targeting of South Korean policy, defense, diplomacy, defector, and related organizations.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN resolver1.opendns.com 2023-05-05 2023-12-18
HASH c0ac380c3dcf94eef84e40ef964a662… 2023-05-05 2023-11-24
URL http://centhosting.net/upload.p… 2023-05-05 2023-11-24
URL http://centhosting.net/list.php… 2023-05-05 2023-11-24
DOMAIN centhosting.net 2023-05-05 2023-11-24
HASH 58d726099fdd9fdb8c34e96e13473aa4 2023-05-05 2023-05-18
HASH 2b2310574eb43608eec2540782e08b35 2023-05-05 2023-05-18
HASH 17718cc9534c10fa30f3ec3d16407e3… 2023-05-05 2023-05-05
HASH 274792046756c6c4e616d653b7d3b24… 2023-05-05 2023-05-05
HASH b20275c27202b202730353733342e7a6 2023-05-05 2023-05-05
HASH 1b415bcc45cfb06c1a649b0a379daae… 2023-05-05 2023-05-05
HASH 027646f63756d656e747327292e436f7 2023-05-05 2023-05-05
HASH 871464a6b762b3d5b636861725d2824… 2023-05-05 2023-05-05
HASH fbe8954a7495380b1f905eb729589f8… 2023-05-05 2023-05-05

Related Actors

Related Reports

« Back