정상 문서로 위장한 악성코드(kimsuky)
2023-02-03 • Ahnlab • Malware disguised as a normal document used by Kimsuky •
AhnLab reports that Kimsuky-linked malicious documents previously seen against security-sector personnel were also being distributed to broadcasting and general enterprise users. The lure documents, including files resembling KBS interview questions and an app-planning document, used template injection to download malicious Word macro templates from compromised Korean web infrastructure. When macros executed, a batch file used curl to fetch a decoy document and a VBS payload, then exfiltrated antivirus, download-folder, and host information while registering scheduled-task persistence. Representative infrastructure included gdtech[.]kr, ddim.co[.]kr, hydrotec.co[.]kr, and jooshineng[.]com paths, with AhnLab detections for DOC.External and DOC.Kimsuky downloaders.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 55a46a2415d18093abcd59a0bf33d0a9 | 2023-02-03 | 2023-10-30 |
| DOMAIN | jooshineng.com | 2023-02-03 | 2023-10-30 |
| HASH | 83b4d96fc75f74bb589c28e8a9eddbbf | 2023-02-03 | 2023-02-15 |
| HASH | 705ef00224f3f7b02e29f21eb6e10d02 | 2023-02-03 | 2023-02-15 |
| HASH | 873b2b0656ee9f6912390b5abc32b276 | 2023-02-03 | 2023-02-15 |
| URL | http://jooshineng.com/gnuboard4… | 2023-02-03 | 2023-02-15 |
| URL | http://www.hydrotec.co.kr/bbs/i… | 2023-02-03 | 2023-02-15 |
| URL | http://gdtech.kr/gnuboard4/adm/… | 2023-02-03 | 2023-02-15 |
| URL | http://www.hydrotec.co.kr/bbs/i… | 2023-02-03 | 2023-02-15 |
| URL | http://ddim.co.kr/gnuboard4/adm… | 2023-02-03 | 2023-02-15 |
| URL | http://gdtech.kr/gnuboard4/adm/… | 2023-02-03 | 2023-02-15 |
| URL | http://ddim.co.kr/gnuboard4/adm… | 2023-02-03 | 2023-02-15 |
| URL | http://www.hydrotec.co.kr/bbs/i… | 2023-02-03 | 2023-02-15 |
| URL | http://gdtech.kr/gnuboard4/adm/… | 2023-02-03 | 2023-02-15 |
| URL | http://gdtech.kr/gnuboard4/adm/… | 2023-02-03 | 2023-02-15 |
| DOMAIN | ddim.co.kr | 2023-02-03 | 2023-02-15 |
| DOMAIN | gdtech.kr | 2023-02-03 | 2023-02-15 |
| HASH | 3cdf9f829ed03e1ac17b72b636d84d0b | 2023-02-03 | 2023-02-03 |