북한 김수키(Kimsuky)에서 만든 악성코드-20241003_20134.docx.lnk(2024.10.3)
2024-10-08 • Sakai • Malware Created by North Korea's Kimsuky - 20241003_20134.docx.lnk (2024.10.3) •
A Kimsuky-linked LNK file named 20241003_20134.docx.lnk is analyzed as a Windows shortcut lure that abuses mshta.exe to launch obfuscated JavaScript and PowerShell. The script connects to 206.206.127.152 on port 9002, stages a ZIP under C:\ProgramData, expands it, runs s.vbs, and deletes temporary artifacts. Decoded VBS content shows persistence through a one-minute scheduled task and a Run registry entry, while later PowerShell code connects to 206.206.127.152 on port 7031 to receive and execute remote commands from a temporary script. The published hashes and staging paths give defenders concrete indicators for hunting Kimsuky shortcut-based delivery and post-execution persistence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 206.206.127.152 | 2024-10-08 | 2025-03-19 |
| HASH | aaecb10ca453bec3bb95bedac6d773a… | 2024-10-08 | 2025-03-12 |
| IPv4 | 6.6.4.1 | 2024-10-08 | 2024-10-14 |
| HASH | c38a378d4d9af72957183cddebb2a65… | 2024-10-08 | 2024-10-08 |
| HASH | 42f3e0840bde6eccd1e17b32b48d6096 | 2024-10-08 | 2024-10-08 |