북한 김수키(Kimsuky)에서 만든 악성코드-1.txt(2024.12.14)
2024-12-24 • Sakai • Malware Created by North Korea's Kimsuky - 1.txt (2024.12.14) •
The report analyzes a Kimsuky-attributed text file containing PowerShell code that downloaded and executed additional scripts from Dropbox-hosted URLs. The script created msupdate.ps1 under the user's AppData path, registered a hidden scheduled task disguised as a Microsoft Edge update task, and repeatedly executed the payload with PowerShell bypass options. Follow-on code collected system details such as IP address, boot time, OS and hardware information, antivirus products, and running processes, uploaded the results through the Dropbox API using embedded OAuth credentials, and deleted local artifacts after upload.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3e1353241852bc3ece184d55f1a2a19… | 2024-12-24 | 2024-12-24 |
| HASH | 71de1f8e9d109354d571df180563cb6… | 2024-12-24 | 2024-12-24 |
| HASH | aa793be3a980534b116c6744b77029e5 | 2024-12-24 | 2024-12-24 |
| URL | https://dl.dropboxusercontent.c… | 2024-12-24 | 2024-12-24 |
| URL | https://dl.dropboxusercontent.c… | 2024-12-24 | 2024-12-24 |