북한 해킹단체 김수키(Kimsuky)에서 만든-위믹스팀-클라우드사용금지.doc(2023.7.28)
2023-08-03 • Sakai • Created by North Korean hacking group Kimsuky - Wemix Team - Cloud use prohibited.doc (2023.7.28) •
The source analyzes a Kimsuky-attributed malicious Word document using a Korean cryptocurrency-themed lure about Wemix cloud-storage precautions. When macros are enabled, the document changes hidden white text to black, copies %windir%\system32\wscript.exe into %appdata% as word.exe, and uses a Base64-decoded URL to fetch script content from partner24.kr/mokozy/hope/kk.php. The downloaded content is decoded into %USERPROFILE%\set.sl and executed with the renamed wscript binary using the vbscript engine. The article lists MD5, SHA-1, and SHA-256 hashes and highlights the misspelled Chnome User-Agent and partner24.kr infrastructure as key indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b6614471ebf288689d33808c376540e1 | 2023-07-31 | 2023-08-09 |
| URL | https://partner24.kr/mokozy/hop… | 2023-07-31 | 2023-08-09 |
| HASH | 84ef8256bece765b0f44dc6d4cf664c… | 2023-08-03 | 2023-08-03 |
| HASH | 928e61590b2c4acf3991bd4327c5107… | 2023-08-03 | 2023-08-03 |
| IPv4 | 172.104.82.74 | 2023-08-03 | 2023-08-03 |