북한 해킹단체 김수키(Kimsuky)에서 만든-위믹스팀-클라우드사용금지.doc(2023.7.28)

2023-08-03 Sakai Created by North Korean hacking group Kimsuky - Wemix Team - Cloud use prohibited.doc (2023.7.28)

https://wezard4u.tistory.com/6530

Thumbnail for 북한 해킹단체 김수키(Kimsuky)에서 만든-위믹스팀-클라우드사용금지.doc(2023.7.28)

The source analyzes a Kimsuky-attributed malicious Word document using a Korean cryptocurrency-themed lure about Wemix cloud-storage precautions. When macros are enabled, the document changes hidden white text to black, copies %windir%\system32\wscript.exe into %appdata% as word.exe, and uses a Base64-decoded URL to fetch script content from partner24.kr/mokozy/hope/kk.php. The downloaded content is decoded into %USERPROFILE%\set.sl and executed with the renamed wscript binary using the vbscript engine. The article lists MD5, SHA-1, and SHA-256 hashes and highlights the misspelled Chnome User-Agent and partner24.kr infrastructure as key indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b6614471ebf288689d33808c376540e1 2023-07-31 2023-08-09
URL https://partner24.kr/mokozy/hop… 2023-07-31 2023-08-09
HASH 84ef8256bece765b0f44dc6d4cf664c… 2023-08-03 2023-08-03
HASH 928e61590b2c4acf3991bd4327c5107… 2023-08-03 2023-08-03
IPv4 172.104.82.74 2023-08-03 2023-08-03

Related Actors

Related Reports

« Back