북한 김수키(Kimsuky)에서 만든 악성 백도어 VBS 스크립트-vbs.html(2025.3.16)

2025-03-19 Sakai Malicious Backdoor VBS Script Created by North Korea's Kimsuky - vbs.html (2025.3.16)

https://wezard4u.tistory.com/429434

Thumbnail for 북한 김수키(Kimsuky)에서 만든 악성 백도어 VBS 스크립트-vbs.html(2025.3.16)

The Korean analysis attributes a malicious VBS backdoor sample named vbs.html to Kimsuky and says it was distributed from hxxp://mrasis(.)n-e(.)kr. The sample is heavily obfuscated, uses random variable names, suppresses errors, decodes hexadecimal strings into executable VBScript, and runs the decoded content through Execute. The decoded logic creates Microsoft XMLHTTP or MSXML2 ServerXMLHTTP objects, sends HTTP POST requests to the same domain, and executes the server response, giving it remote command execution and backdoor behavior. The report identifies mrasis(.)n-e(.)kr as command-and-control infrastructure and provides MD5, SHA-1, and SHA-256 hashes for the sample to support detection and hunting.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://mrasis.n-e.kr/comarov/se… 2025-03-19 2025-07-08
HASH a6598bbdc947286c84f951289d14425c 2025-03-17 2025-07-08
DOMAIN mrasis.n-e.kr 2025-03-17 2025-07-08
URL http://mrasis.n-e.kr/comarov/se… 2025-03-19 2025-03-19
URL http://mrasis.n-e.kr 2025-03-19 2025-03-19
HASH 07c7cf4441254e8754aa62150bf8c53… 2025-03-17 2025-03-19
HASH 5f23b1ca43f6a18e3c9f21d390f5d1e… 2025-03-17 2025-03-19
URL http://mrasis.n-e.kr/ 2025-03-17 2025-03-19

Related Actors

Related Reports

« Back