북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-강연의뢰서_엄구호 교수님.docx.lnk(2024.6.4)
2024-06-28 • Sakai • Kimsuky Malware Disguised as a Lecture Request Document LNK •
A Kimsuky-attributed Windows LNK sample masqueraded as a lecture-request document for a Hanyang University professor, suggesting a social-engineering attempt against South Korean academic or policy-focused contacts. The shortcut executed hidden PowerShell, searched for the crafted LNK by file size, extracted and ran an embedded executable, deleted the original shortcut, and displayed a decoy Word document named 123.docx. The script used hardcoded Dropbox OAuth credentials to obtain an access token, download /0603/ps.bin from Dropbox, decode it with a custom routine, and execute the decoded PowerShell content with Invoke-Expression. The excerpt provides file hashes and multiple antivirus detections, making the sample useful for endpoint hunting and tracking document-themed DPRK phishing tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 52d073c181531c7f0b8b3aa764c6551d | 2024-06-28 | 2024-10-04 |
| HASH | 3065b8e4bb91b4229d1cea671e8959d… | 2024-06-28 | 2024-06-28 |
| HASH | a64e0a2e0a9b213966e6325efecc5e0… | 2024-06-28 | 2024-06-28 |
| URL | https://content.dropboxapi.com/… | 2024-06-28 | 2024-06-28 |