북한 해킹 단체 김수키(Kimsuky)에서 만든 스피어 피싱으로 제작된 악성코드-열차9월10일원고(화)_4.bat(2024.12.02)
2024-12-17 • Sakai • Malware Crafted for Spear Phishing by the North Korean Hacking Group Kimsuky - Train September 10 Manuscript (Tuesday)_4.bat (2024.12.02) •
A Korean-language malware analysis attributes a BAT-file spear-phishing sample to Kimsuky and says the lure appears aimed at a Korean broadcast production team working on North Korea-related programming. The script launches 32-bit PowerShell in a hidden window, reads elephant.dat from the temporary directory, converts it into a script block, and executes it. The follow-on code reads caption.dat, XOR-decodes it with the key "d", allocates executable memory through kernel32.dll APIs, and runs the decoded payload in a new thread. The source provides hashes for the BAT sample, including SHA-256 5306582c8a24508b594fed478d5abaa5544389c86ba507d8ebf98c5c7edde451, giving defenders concrete indicators for Kimsuky-linked script execution and memory-resident payload loading.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5306582c8a24508b594fed478d5abaa… | 2024-12-17 | 2025-03-10 |
| HASH | 5b191427f2d47efe8a8e7bb195f1b4a… | 2024-12-17 | 2024-12-17 |
| HASH | c0b447e45be32bd6ceba8c6455472b37 | 2024-12-17 | 2024-12-17 |