우리 민족의 해킹단체 북한 김수키(Kimsuky) 만든 파워셀 악성코드-pow.ps1(2024.9.23)

2024-10-01 Sakai PowerShell Malware Created by North Korea's Kimsuky - pow.ps1 (2024.9.23)

http://wezard4u.tistory.com/429289

Thumbnail for 우리 민족의 해킹단체 북한 김수키(Kimsuky) 만든 파워셀 악성코드-pow.ps1(2024.9.23)

The source analyzes a Kimsuky PowerShell malware sample associated with North Korean activity. The archive preserves technical evidence rather than a narrative article, including SHA-256 hash 751698edee5ec4c46fddaa995f120984dfd551e1f68fc2d0fea7bfe1a8868c83, mutex logic, obfuscated PowerShell and .NET code fragments, and file-handling routines. The indicators support a focused malware-analysis record for defenders tracking Kimsuky tooling and script-based intrusion tradecraft, but the article should be reviewed with the linked source before deriving victimology or campaign-level conclusions beyond the malware family and actor label present in the report.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8dd3ff59320a5908f60755232b766c7… 2024-10-01 2024-10-01
HASH 751698edee5ec4c46fddaa995f12098… 2024-10-01 2024-10-01
DOMAIN ck.org 2024-09-26 2024-10-01
HASH c8d589ac5c872b12e502ec1fc2fee0c7 2023-10-16 2024-10-01

Related Actors

Related Reports

« Back