북한 김수키(Kimsuky)에서 제작한 악성코드-ofx.txt(2025.6.11)
2025-09-16 • Sakai • Malware Created by North Korean Kimsuky - ofx.txt (2025.6.11) •
The excerpt attributes an OFX text-stage script from the “Update Schedule_INVITATION - 250625 UNC Ambassador's Roundtable” archive to Kimsuky activity using a diplomatic-themed lure. The PowerShell collects host profiling data, including the first network adapter IP address, timestamp, last boot time, OS and system details, process listings, and potentially antivirus product information. It writes the collected data under %APPDATA% using an IP-and-time-based filename, Base64-encodes the file, and uploads it to the landjhon/world GitHub repository through the GitHub Contents API. The script uses light string-splitting obfuscation, a hard-coded GitHub personal access token, and deletes the local artifact after upload, showing SaaS-based data exfiltration and cleanup.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.32.133.19 | 2025-09-08 | 2025-09-17 |
| HASH | 6bb053ca180dcbc3e1d37b2e6ec1cdf1 | 2025-09-16 | 2025-09-16 |
| HASH | 59ed600b44adc7cb5ac2156e4ff683a… | 2025-09-16 | 2025-09-16 |
| HASH | 932f33336632a388c2d2cfb0560c773… | 2025-09-16 | 2025-09-16 |
| DOMAIN | ub.com | 2025-09-16 | 2025-09-16 |