북한 김수키(Kimsuky)추측 되는 상여금 계산 엑셀 파일로 위장한 악성코드-상여금처리산식.xls(2022.11.04)
2025-07-25 • Sakai • Malware Suspected to Be North Korean Kimsuky, Disguised as a Bonus Calculation Excel File - Bonus Processing Formula.xls (2022.11.04) •
A Korean analysis examines a suspected Kimsuky-linked Excel malware sample disguised as a bonus calculation spreadsheet. The workbook uses macros to read a download URL from Sheet1 cell A10001, escape command characters, and invoke curl through cmd.exe to save fileDownloader.exe in the user's TEMP directory. The macro code references Windows registry APIs and a download path on 106.249.253.146:12582, with hashes provided for the spreadsheet sample. The lure contains payroll and benefit fields, suggesting a Korean administrative or workplace theme, while the author notes North Korean operators target civilians, companies, and North Korea-related personnel without narrowing the victim set further.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | soubtcevent.com | 2025-07-25 | 2025-07-30 |
| HASH | c74441bb3efbd6243efde0045134c7c… | 2025-07-25 | 2025-07-25 |
| HASH | 07a2105937ab7f4c610bc1eefb784a29 | 2025-07-25 | 2025-07-25 |
| HASH | 645c0ef504d47a55ca1aa25a501d66e… | 2025-07-25 | 2025-07-25 |
| IPv4 | 106.249.253.146 | 2025-07-25 | 2025-07-25 |