북한 김수키(Kimsuky)에서 만든 악성코드-미신고 자금출처 해명 자료 제출 안내(부가치세법 시행 규칙)
2025-10-14 • Sakai • Kimsuky-themed malware analysis report •
A Korean malware analysis attributes a malicious shortcut file themed as an undeclared funding-source explanation notice to Kimsuky activity against South Korean users. The LNK launches obfuscated PowerShell that searches for a 35,265-byte shortcut, extracts 18,432 bytes from offset 0x18CC, XOR-decodes the embedded payload with key 0x99, writes and executes it, then deletes the original shortcut. The follow-on command chain copies curl.exe and schtasks.exe into C:\Users\Public\Documents under renamed filenames, downloads AutoIt3.exe and PpkuFag.cdr from m2view.com.py under /wp-admin/js/widgets/hurryup/, and creates a scheduled task named PpkuFag to run every minute. The report provides hashes for the LNK and shows persistence and payload retrieval implemented through renamed legitimate Windows utilities and AutoIt execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fc44d9c71b71c58b3bfbb66479355f71 | 2025-10-14 | 2025-10-14 |
| HASH | 0c79620d6b36625655881d04ae4f9b2… | 2025-10-14 | 2025-10-14 |
| HASH | 905814fd03e901c31b63c411fea0014… | 2025-10-14 | 2025-10-14 |
| URL | https://m2view.com.py/wp-admin/… | 2025-10-14 | 2025-10-14 |
| URL | https://m2view.com.py/wp-admin/… | 2025-10-14 | 2025-10-14 |
| URL | https://m2view.com.py/wp-admin/… | 2025-10-14 | 2025-10-14 |
| URL | https://m2view.com.py/wp-admin/… | 2025-10-14 | 2025-10-14 |
| URL | https://m2view.com.py/wp-admin/… | 2025-10-14 | 2025-10-14 |
| DOMAIN | m2view.com.py | 2025-10-14 | 2025-10-14 |