우리 민족의 해킹단체 북한 김수키(Kimsuky) 만든 파워셀 악성코드-pow.ps1(2024.9.23)
2024-10-01 • Sakai • PowerShell Malware Created by North Korea's Kimsuky - pow.ps1 (2024.9.23) •
The source analyzes a Kimsuky PowerShell malware sample associated with North Korean activity. The archive preserves technical evidence rather than a narrative article, including SHA-256 hash 751698edee5ec4c46fddaa995f120984dfd551e1f68fc2d0fea7bfe1a8868c83, mutex logic, obfuscated PowerShell and .NET code fragments, and file-handling routines. The indicators support a focused malware-analysis record for defenders tracking Kimsuky tooling and script-based intrusion tradecraft, but the article should be reviewed with the linked source before deriving victimology or campaign-level conclusions beyond the malware family and actor label present in the report.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8dd3ff59320a5908f60755232b766c7… | 2024-10-01 | 2024-10-01 |
| HASH | 751698edee5ec4c46fddaa995f12098… | 2024-10-01 | 2024-10-01 |
| DOMAIN | ck.org | 2024-09-26 | 2024-10-01 |
| HASH | c8d589ac5c872b12e502ec1fc2fee0c7 | 2023-10-16 | 2024-10-01 |