북한 김수키(Kimsuky)에서 만든 워드 악성코드-인적사항.doc(2023.4.11)
2023-04-14 • Sakai • Word malware created by Kimsuky in North Korea - personal information.doc (2023.4.11) •
A Korean analysis attributes a malicious Word document named like a personal-information/resume form to Kimsuky, describing a VBA macro that runs only after macros are enabled. The macro uses obfuscated string replacement and Shell.Application to launch PowerShell, download and execute a remote script from mvix.xn--oi2b61z32a.xn--3e0b707e, and spawn Windows processes such as svchost and wmiprvse. The source lists hashes for the document and representative network indicators including 145.14.144.206, 145.14.145.122, 145.14.145.245, and URLs under /ej/li.txt, /ej/li.rong, and /ej/index.php?filename=li. The report is relevant to DPRK tracking because it documents Kimsuky tradecraft using a Korean-language lure document, macro obfuscation, and remote PowerShell payload retrieval.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 91d0b01a6a4a0b8edadf1df6a8e68d20 | 2023-04-14 | 2023-08-28 |
| HASH | b39ac30367d9aa2d915e7ce5d102694… | 2023-04-14 | 2023-04-14 |
| HASH | 0d663b9907a34604f120963b64a763c… | 2023-04-14 | 2023-04-14 |
| IPv4 | 145.14.145.245 | 2023-04-14 | 2023-04-14 |
| IPv4 | 145.14.145.122 | 2023-04-14 | 2023-04-14 |
| IPv4 | 145.14.144.206 | 2023-04-14 | 2023-04-14 |