북한 김수키(Kimsuky)워드 악성코드-협의 이혼 의사 확인 신청서.doc

2023-03-17 Sakai North Korea Kimsuky word malware - application for confirmation of intention to divorce by agreement.doc

https://wezard4u.tistory.com/6393

Thumbnail for 북한 김수키(Kimsuky)워드 악성코드-협의 이혼 의사 확인 신청서.doc

The source analyzes a Kimsuky-linked malicious Word document named as a mutual-divorce intent confirmation application, a lure also associated with North Korea-focused targeting in South Korea. The macro-enabled document displays a divorce form decoy but runs AutoOpen code that writes version.ini under the user’s Microsoft Templates path and launches it with wscript.exe. The script retrieves further code from a Google Drive download URL, establishes persistence through scheduled tasks and follow-on scripts, and ultimately supports QuasarRAT-style remote access behavior including account and system information collection and file transfer. The report provides file hashes for the document and notes network activity to Google infrastructure during payload retrieval.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e0cf0881de0fe35732bb02c1f4df02a3 2023-03-15 2023-05-24
HASH 3978abfd510cafbda865b708d689656… 2023-03-17 2023-03-17
HASH 00002109f10090400000000000f01fec 2023-03-17 2023-03-17
HASH e8475fe3ac277d2eda466aaa4d42044… 2023-03-17 2023-03-17
HASH 00002109b10090400000000000f01fec 2023-03-17 2023-03-17
IPv4 142.250.181.238 2023-03-17 2023-03-17

Related Actors

Related Reports

« Back