북한 해킹 단체 김수키(Kimsuky)에서 만든 저작권 사칭 관련 악성코드-저작권관련내역.url(2025.3.21)
2025-03-25 • Sakai • Kimsuky malware related to copyright impersonation using Copyright Details.url, March 21 2025 •
A Kimsuky-themed analysis examines a copyright-related lure delivered as a Windows .url shortcut file named to look like copyright documentation. The shortcut uses an Edge browser icon and a crafted file:// URL referencing invoice-docs-file[.]site and ready.pif, encouraging the user to treat the item as a benign browser shortcut while reaching executable content. The domain is described as associated with malware activity, listed in Spamhaus DBL, and commonly used in phishing, while the .pif payload format is noted as an executable Windows artifact often used to evade user expectations. The excerpt provides hashes for the analyzed file and highlights that only BitDefender-related engines were detecting it at the cited time, supporting defensive hunting for suspicious copyright-themed .url lures and .pif retrieval attempts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 755e3c5c62ac683bbea831255c4ee3b… | 2025-03-25 | 2025-03-25 |
| HASH | 2e6ab2f8e5a24c9d9acde16589cfd34… | 2025-03-25 | 2025-03-25 |
| HASH | 66bd429d02479a029a25ccacc0d134b3 | 2025-03-25 | 2025-03-25 |