북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-강연의뢰서_엄구호 교수님.docx.lnk(2024.6.4)

2024-06-28 Sakai Kimsuky Malware Disguised as a Lecture Request Document LNK

http://wezard4u.tistory.com/6843

Thumbnail for 북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-강연의뢰서_엄구호 교수님.docx.lnk(2024.6.4)

A Kimsuky-attributed Windows LNK sample masqueraded as a lecture-request document for a Hanyang University professor, suggesting a social-engineering attempt against South Korean academic or policy-focused contacts. The shortcut executed hidden PowerShell, searched for the crafted LNK by file size, extracted and ran an embedded executable, deleted the original shortcut, and displayed a decoy Word document named 123.docx. The script used hardcoded Dropbox OAuth credentials to obtain an access token, download /0603/ps.bin from Dropbox, decode it with a custom routine, and execute the decoded PowerShell content with Invoke-Expression. The excerpt provides file hashes and multiple antivirus detections, making the sample useful for endpoint hunting and tracking document-themed DPRK phishing tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 52d073c181531c7f0b8b3aa764c6551d 2024-06-28 2024-10-04
HASH 3065b8e4bb91b4229d1cea671e8959d… 2024-06-28 2024-06-28
HASH a64e0a2e0a9b213966e6325efecc5e0… 2024-06-28 2024-06-28
URL https://content.dropboxapi.com/… 2024-06-28 2024-06-28

Related Actors

Related Reports

« Back