북한 김수키(Kimsuky) 세종연구소 한반도전략센터장 을 사칭 하는 악성코드-CHEONG ??? Chang Essay FINAL.msc(2024.9.25)

2024-10-30 Sakai Malware by North Korea's Kimsuky Impersonating the Director of the Sejong Institute's Center for Korean Peninsula Strategy - CHEONG Chang Essay FINAL.msc (2024.9.25)

https://wezard4u.tistory.com/429312

Thumbnail for 북한 김수키(Kimsuky) 세종연구소 한반도전략센터장 을 사칭 하는 악성코드-CHEONG ??? Chang Essay FINAL.msc(2024.9.25)

The Wezard4u post analyzes a Kimsuky-linked MSC lure that impersonated the Sejong Institute's Center for Korean Peninsula Strategy director to target people working on North Korea issues. The malicious command sequence used curl to retrieve a decoy DOCX, a sim.exe payload, a scheduled-task XML file, and a manifest from main.dkwis.kro.kr over port 8000. It created a Windows scheduled task named TemporaryClearStatessdfse for persistence and hid execution in a minimized cmd.exe window while presenting the victim with a document. The source lists hashes for the MSC sample and shows the operation's social-engineering focus on Korean users and policy communities.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN telegram-df.org 2024-10-30 2024-11-04
HASH fd65c7a42458d05219cd6dad15b8ba2… 2024-10-30 2024-10-30
HASH 1080b6fb2060cda252145548d1624a2… 2024-10-30 2024-10-30
HASH 90a7f83dd9cf5e58044cdf56e8ed7079 2024-10-30 2024-10-30
URL http://main.dkwis.kro.kr:8000/0… 2024-10-30 2024-10-30
URL http://main.dkwis.kro.kr:8000/0… 2024-10-30 2024-10-30
URL http://main.dkwis.kro.kr:8000/0 2024-10-30 2024-10-30
URL http://main.dkwis.kro.kr:8000/0… 2024-10-30 2024-10-30
URL http://main.dkwis.kro.kr:8000 2024-10-30 2024-10-30
URL http://main.dkwis.kro.kr:8000/0… 2024-10-30 2024-10-30
DOMAIN s.kro.kr 2024-10-30 2024-10-30
DOMAIN main.dkwis.kro.kr 2024-10-30 2024-10-30
IPv4 121.66.72.110 2024-10-30 2024-10-30

Related Actors

Related Reports

« Back