북한 김수키(Kimsuky)에서 만든 워드 악성코드-인적사항.doc(2023.4.11)

2023-04-14 Sakai Word malware created by Kimsuky in North Korea - personal information.doc (2023.4.11)

https://wezard4u.tistory.com/6417

Thumbnail for 북한 김수키(Kimsuky)에서 만든 워드 악성코드-인적사항.doc(2023.4.11)

A Korean analysis attributes a malicious Word document named like a personal-information/resume form to Kimsuky, describing a VBA macro that runs only after macros are enabled. The macro uses obfuscated string replacement and Shell.Application to launch PowerShell, download and execute a remote script from mvix.xn--oi2b61z32a.xn--3e0b707e, and spawn Windows processes such as svchost and wmiprvse. The source lists hashes for the document and representative network indicators including 145.14.144.206, 145.14.145.122, 145.14.145.245, and URLs under /ej/li.txt, /ej/li.rong, and /ej/index.php?filename=li. The report is relevant to DPRK tracking because it documents Kimsuky tradecraft using a Korean-language lure document, macro obfuscation, and remote PowerShell payload retrieval.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 91d0b01a6a4a0b8edadf1df6a8e68d20 2023-04-14 2023-08-28
HASH b39ac30367d9aa2d915e7ce5d102694… 2023-04-14 2023-04-14
HASH 0d663b9907a34604f120963b64a763c… 2023-04-14 2023-04-14
IPv4 145.14.145.245 2023-04-14 2023-04-14
IPv4 145.14.145.122 2023-04-14 2023-04-14
IPv4 145.14.144.206 2023-04-14 2023-04-14

Related Actors

Related Reports

« Back