북한 김수키(Kimsuky)추측 되는 상여금 계산 엑셀 파일로 위장한 악성코드-상여금처리산식.xls(2022.11.04)

2025-07-25 Sakai Malware Suspected to Be North Korean Kimsuky, Disguised as a Bonus Calculation Excel File - Bonus Processing Formula.xls (2022.11.04)

https://wezard4u.tistory.com/429548

Thumbnail for 북한 김수키(Kimsuky)추측 되는 상여금 계산 엑셀 파일로 위장한 악성코드-상여금처리산식.xls(2022.11.04)

A Korean analysis examines a suspected Kimsuky-linked Excel malware sample disguised as a bonus calculation spreadsheet. The workbook uses macros to read a download URL from Sheet1 cell A10001, escape command characters, and invoke curl through cmd.exe to save fileDownloader.exe in the user's TEMP directory. The macro code references Windows registry APIs and a download path on 106.249.253.146:12582, with hashes provided for the spreadsheet sample. The lure contains payroll and benefit fields, suggesting a Korean administrative or workplace theme, while the author notes North Korean operators target civilians, companies, and North Korea-related personnel without narrowing the victim set further.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN soubtcevent.com 2025-07-25 2025-07-30
HASH c74441bb3efbd6243efde0045134c7c… 2025-07-25 2025-07-25
HASH 07a2105937ab7f4c610bc1eefb784a29 2025-07-25 2025-07-25
HASH 645c0ef504d47a55ca1aa25a501d66e… 2025-07-25 2025-07-25
IPv4 106.249.253.146 2025-07-25 2025-07-25

Related Actors

Related Reports

« Back