북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-근로신청서 관련의 건.docx.lnk(2024.7.9)

2024-07-17 Sakai Kimsuky malware disguised as an employment application document shortcut

https://wezard4u.tistory.com/429233

Thumbnail for 북한 해킹 단체 김수키(Kimsuky)에서 만든 악성코드-근로신청서 관련의 건.docx.lnk(2024.7.9)

The Korean source attributes a malicious Windows shortcut disguised as an employment application document to Kimsuky. The LNK launches obfuscated PowerShell with execution-policy bypass, decodes embedded Base64 script content, searches for matching shortcut files, and extracts additional data from the LNK. Execution creates VBS and temporary files under ProgramData, runs them with wscript.exe, and uses Dropbox API upload and download endpoints for network activity. The report provides hashes for the lure and notes antivirus detections for the LNK dropper.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
HASH 21d12dc7f08752293847af6ed19df0e3 2024-07-17 2024-09-05
HASH 5074647737b8b996b597c1719b571cc… 2024-07-17 2024-07-17
HASH e7e73a5133cd61c077f85c44e9efeb8… 2024-07-17 2024-07-17

Related Actors

Related Reports

« Back