북한 김수키(Kimsuky)에서 만든 악성코드-20241003_20134.docx.lnk(2024.10.3)

2024-10-08 Sakai Malware Created by North Korea's Kimsuky - 20241003_20134.docx.lnk (2024.10.3)

http://wezard4u.tistory.com/429294

Thumbnail for 북한 김수키(Kimsuky)에서 만든 악성코드-20241003_20134.docx.lnk(2024.10.3)

A Kimsuky-linked LNK file named 20241003_20134.docx.lnk is analyzed as a Windows shortcut lure that abuses mshta.exe to launch obfuscated JavaScript and PowerShell. The script connects to 206.206.127.152 on port 9002, stages a ZIP under C:\ProgramData, expands it, runs s.vbs, and deletes temporary artifacts. Decoded VBS content shows persistence through a one-minute scheduled task and a Run registry entry, while later PowerShell code connects to 206.206.127.152 on port 7031 to receive and execute remote commands from a temporary script. The published hashes and staging paths give defenders concrete indicators for hunting Kimsuky shortcut-based delivery and post-execution persistence.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 206.206.127.152 2024-10-08 2025-03-19
HASH aaecb10ca453bec3bb95bedac6d773a… 2024-10-08 2025-03-12
IPv4 6.6.4.1 2024-10-08 2024-10-14
HASH c38a378d4d9af72957183cddebb2a65… 2024-10-08 2024-10-08
HASH 42f3e0840bde6eccd1e17b32b48d6096 2024-10-08 2024-10-08

Related Actors

Related Reports

« Back