북한 김수키(Kimsuky)에서 만든 악성 백도어 VBS 스크립트-vbs.html(2025.3.16)
2025-03-19 • Sakai • Malicious Backdoor VBS Script Created by North Korea's Kimsuky - vbs.html (2025.3.16) •
The Korean analysis attributes a malicious VBS backdoor sample named vbs.html to Kimsuky and says it was distributed from hxxp://mrasis(.)n-e(.)kr. The sample is heavily obfuscated, uses random variable names, suppresses errors, decodes hexadecimal strings into executable VBScript, and runs the decoded content through Execute. The decoded logic creates Microsoft XMLHTTP or MSXML2 ServerXMLHTTP objects, sends HTTP POST requests to the same domain, and executes the server response, giving it remote command execution and backdoor behavior. The report identifies mrasis(.)n-e(.)kr as command-and-control infrastructure and provides MD5, SHA-1, and SHA-256 hashes for the sample to support detection and hunting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://mrasis.n-e.kr/comarov/se… | 2025-03-19 | 2025-07-08 |
| HASH | a6598bbdc947286c84f951289d14425c | 2025-03-17 | 2025-07-08 |
| DOMAIN | mrasis.n-e.kr | 2025-03-17 | 2025-07-08 |
| URL | http://mrasis.n-e.kr/comarov/se… | 2025-03-19 | 2025-03-19 |
| URL | http://mrasis.n-e.kr | 2025-03-19 | 2025-03-19 |
| HASH | 07c7cf4441254e8754aa62150bf8c53… | 2025-03-17 | 2025-03-19 |
| HASH | 5f23b1ca43f6a18e3c9f21d390f5d1e… | 2025-03-17 | 2025-03-19 |
| URL | http://mrasis.n-e.kr/ | 2025-03-17 | 2025-03-19 |