북한 김수키(Kimsuky)에서 만든 악성코드-미신고 자금출처 해명 자료 제출 안내(부가치세법 시행 규칙)

2025-10-14 Sakai Kimsuky-themed malware analysis report

https://wezard4u.tistory.com/429619

Thumbnail for 북한 김수키(Kimsuky)에서 만든 악성코드-미신고 자금출처 해명 자료 제출 안내(부가치세법 시행 규칙)

A Korean malware analysis attributes a malicious shortcut file themed as an undeclared funding-source explanation notice to Kimsuky activity against South Korean users. The LNK launches obfuscated PowerShell that searches for a 35,265-byte shortcut, extracts 18,432 bytes from offset 0x18CC, XOR-decodes the embedded payload with key 0x99, writes and executes it, then deletes the original shortcut. The follow-on command chain copies curl.exe and schtasks.exe into C:\Users\Public\Documents under renamed filenames, downloads AutoIt3.exe and PpkuFag.cdr from m2view.com.py under /wp-admin/js/widgets/hurryup/, and creates a scheduled task named PpkuFag to run every minute. The report provides hashes for the LNK and shows persistence and payload retrieval implemented through renamed legitimate Windows utilities and AutoIt execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fc44d9c71b71c58b3bfbb66479355f71 2025-10-14 2025-10-14
HASH 0c79620d6b36625655881d04ae4f9b2… 2025-10-14 2025-10-14
HASH 905814fd03e901c31b63c411fea0014… 2025-10-14 2025-10-14
URL https://m2view.com.py/wp-admin/… 2025-10-14 2025-10-14
URL https://m2view.com.py/wp-admin/… 2025-10-14 2025-10-14
URL https://m2view.com.py/wp-admin/… 2025-10-14 2025-10-14
URL https://m2view.com.py/wp-admin/… 2025-10-14 2025-10-14
URL https://m2view.com.py/wp-admin/… 2025-10-14 2025-10-14
DOMAIN m2view.com.py 2025-10-14 2025-10-14

Related Actors

Related Reports

« Back