북한 김수키(Kimsuky) 세종연구소 한반도전략센터장 을 사칭 하는 악성코드-CHEONG ??? Chang Essay FINAL.msc(2024.9.25)
2024-10-30 • Sakai • Malware by North Korea's Kimsuky Impersonating the Director of the Sejong Institute's Center for Korean Peninsula Strategy - CHEONG Chang Essay FINAL.msc (2024.9.25) •
The Wezard4u post analyzes a Kimsuky-linked MSC lure that impersonated the Sejong Institute's Center for Korean Peninsula Strategy director to target people working on North Korea issues. The malicious command sequence used curl to retrieve a decoy DOCX, a sim.exe payload, a scheduled-task XML file, and a manifest from main.dkwis.kro.kr over port 8000. It created a Windows scheduled task named TemporaryClearStatessdfse for persistence and hid execution in a minimized cmd.exe window while presenting the victim with a document. The source lists hashes for the MSC sample and shows the operation's social-engineering focus on Korean users and policy communities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | telegram-df.org | 2024-10-30 | 2024-11-04 |
| HASH | fd65c7a42458d05219cd6dad15b8ba2… | 2024-10-30 | 2024-10-30 |
| HASH | 1080b6fb2060cda252145548d1624a2… | 2024-10-30 | 2024-10-30 |
| HASH | 90a7f83dd9cf5e58044cdf56e8ed7079 | 2024-10-30 | 2024-10-30 |
| URL | http://main.dkwis.kro.kr:8000/0… | 2024-10-30 | 2024-10-30 |
| URL | http://main.dkwis.kro.kr:8000/0… | 2024-10-30 | 2024-10-30 |
| URL | http://main.dkwis.kro.kr:8000/0 | 2024-10-30 | 2024-10-30 |
| URL | http://main.dkwis.kro.kr:8000/0… | 2024-10-30 | 2024-10-30 |
| URL | http://main.dkwis.kro.kr:8000 | 2024-10-30 | 2024-10-30 |
| URL | http://main.dkwis.kro.kr:8000/0… | 2024-10-30 | 2024-10-30 |
| DOMAIN | s.kro.kr | 2024-10-30 | 2024-10-30 |
| DOMAIN | main.dkwis.kro.kr | 2024-10-30 | 2024-10-30 |
| IPv4 | 121.66.72.110 | 2024-10-30 | 2024-10-30 |