북한 해킹 단체 김수키(Kimsuky)에서 만든 스피어 피싱으로 제작된 악성코드-열차9월10일원고(화)_4.bat(2024.12.02)

2024-12-17 Sakai Malware Crafted for Spear Phishing by the North Korean Hacking Group Kimsuky - Train September 10 Manuscript (Tuesday)_4.bat (2024.12.02)

https://wezard4u.tistory.com/429357

Thumbnail for 북한 해킹 단체 김수키(Kimsuky)에서 만든 스피어 피싱으로 제작된 악성코드-열차9월10일원고(화)_4.bat(2024.12.02)

A Korean-language malware analysis attributes a BAT-file spear-phishing sample to Kimsuky and says the lure appears aimed at a Korean broadcast production team working on North Korea-related programming. The script launches 32-bit PowerShell in a hidden window, reads elephant.dat from the temporary directory, converts it into a script block, and executes it. The follow-on code reads caption.dat, XOR-decodes it with the key "d", allocates executable memory through kernel32.dll APIs, and runs the decoded payload in a new thread. The source provides hashes for the BAT sample, including SHA-256 5306582c8a24508b594fed478d5abaa5544389c86ba507d8ebf98c5c7edde451, giving defenders concrete indicators for Kimsuky-linked script execution and memory-resident payload loading.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5306582c8a24508b594fed478d5abaa… 2024-12-17 2025-03-10
HASH 5b191427f2d47efe8a8e7bb195f1b4a… 2024-12-17 2024-12-17
HASH c0b447e45be32bd6ceba8c6455472b37 2024-12-17 2024-12-17

Related Actors

Related Reports

« Back