북한 김수키(Kimsuky)에서 만든 악성코드-1.txt(2024.12.14)

2024-12-24 Sakai Malware Created by North Korea's Kimsuky - 1.txt (2024.12.14)

https://wezard4u.tistory.com/429363

Thumbnail for 북한 김수키(Kimsuky)에서 만든 악성코드-1.txt(2024.12.14)

The report analyzes a Kimsuky-attributed text file containing PowerShell code that downloaded and executed additional scripts from Dropbox-hosted URLs. The script created msupdate.ps1 under the user's AppData path, registered a hidden scheduled task disguised as a Microsoft Edge update task, and repeatedly executed the payload with PowerShell bypass options. Follow-on code collected system details such as IP address, boot time, OS and hardware information, antivirus products, and running processes, uploaded the results through the Dropbox API using embedded OAuth credentials, and deleted local artifacts after upload.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3e1353241852bc3ece184d55f1a2a19… 2024-12-24 2024-12-24
HASH 71de1f8e9d109354d571df180563cb6… 2024-12-24 2024-12-24
HASH aa793be3a980534b116c6744b77029e5 2024-12-24 2024-12-24
URL https://dl.dropboxusercontent.c… 2024-12-24 2024-12-24
URL https://dl.dropboxusercontent.c… 2024-12-24 2024-12-24

Related Actors

Related Reports

« Back