북한 김수키(Kimsuky)워드 악성코드-협의 이혼 의사 확인 신청서.doc
2023-03-17 • Sakai • North Korea Kimsuky word malware - application for confirmation of intention to divorce by agreement.doc •
The source analyzes a Kimsuky-linked malicious Word document named as a mutual-divorce intent confirmation application, a lure also associated with North Korea-focused targeting in South Korea. The macro-enabled document displays a divorce form decoy but runs AutoOpen code that writes version.ini under the user’s Microsoft Templates path and launches it with wscript.exe. The script retrieves further code from a Google Drive download URL, establishes persistence through scheduled tasks and follow-on scripts, and ultimately supports QuasarRAT-style remote access behavior including account and system information collection and file transfer. The report provides file hashes for the document and notes network activity to Google infrastructure during payload retrieval.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e0cf0881de0fe35732bb02c1f4df02a3 | 2023-03-15 | 2023-05-24 |
| HASH | 3978abfd510cafbda865b708d689656… | 2023-03-17 | 2023-03-17 |
| HASH | 00002109f10090400000000000f01fec | 2023-03-17 | 2023-03-17 |
| HASH | e8475fe3ac277d2eda466aaa4d42044… | 2023-03-17 | 2023-03-17 |
| HASH | 00002109b10090400000000000f01fec | 2023-03-17 | 2023-03-17 |
| IPv4 | 142.250.181.238 | 2023-03-17 | 2023-03-17 |