북한 김수키(Kimsuky)에서 만든 악성코드-미신고 자금 출처명세서(찾아가는 법 찾기).zip(2025.6.4)
2025-06-23 • Sakai • Malware Created by North Korean Kimsuky - Unreported Source of Funds Statement (How to Find Visiting Legal Services).zip (2025.6.4) •
The Korean write-up attributes a tax-themed malware lure to Kimsuky and assesses that it was likely intended for email delivery to victims. The archive contained decoy HWP tax documents and a key HWP-themed LNK file that ran obfuscated PowerShell, searched for a marker-sized shortcut, decoded embedded bytes with XOR, executed the extracted payload, and removed the shortcut artifact. The follow-on command copied curl.exe and schtasks.exe into C:\Users\Public\Videos under renamed filenames, downloaded AutoIt3.exe and a CDR payload from thegreatratings[.]com, and created a scheduled task named CfjiFUW to run every minute. The lure abused South Korean tax and undeclared-funds documentation themes, making it relevant to DPRK tracking of Kimsuky social engineering against Korean-language targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b24b1aa0a95e1c1a594bd8b34877fa1… | 2025-06-23 | 2025-06-23 |
| HASH | f1aa607507e97cf2dee3d3059d3b2b1… | 2025-06-23 | 2025-06-23 |
| HASH | 31bd1480d76972b1727c9ef6953741f… | 2025-06-23 | 2025-06-23 |
| HASH | 2d516c97e510bbdfb89eae329b88e0b… | 2025-06-23 | 2025-06-23 |
| HASH | cc72c5bf20e8d5d6efa66dfc1d8efaa4 | 2025-06-23 | 2025-06-23 |
| HASH | e2328974ecc81be06619bbd06ebfacb4 | 2025-06-23 | 2025-06-23 |
| URL | https://thegreatratings.com/wp-… | 2025-06-23 | 2025-06-23 |
| DOMAIN | ngs.com | 2025-06-23 | 2025-06-23 |
| DOMAIN | thegreatratings.com | 2025-06-23 | 2025-06-23 |
| IPv4 | 66.96.162.245 | 2025-06-23 | 2025-06-23 |