정상 문서로 위장한 악성코드(kimsuky)

2023-02-03 Ahnlab Malware disguised as a normal document used by Kimsuky

https://asec.ahnlab.com/ko/47147/

Thumbnail for 정상 문서로 위장한 악성코드(kimsuky)

AhnLab reports that Kimsuky-linked malicious documents previously seen against security-sector personnel were also being distributed to broadcasting and general enterprise users. The lure documents, including files resembling KBS interview questions and an app-planning document, used template injection to download malicious Word macro templates from compromised Korean web infrastructure. When macros executed, a batch file used curl to fetch a decoy document and a VBS payload, then exfiltrated antivirus, download-folder, and host information while registering scheduled-task persistence. Representative infrastructure included gdtech[.]kr, ddim.co[.]kr, hydrotec.co[.]kr, and jooshineng[.]com paths, with AhnLab detections for DOC.External and DOC.Kimsuky downloaders.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 55a46a2415d18093abcd59a0bf33d0a9 2023-02-03 2023-10-30
DOMAIN jooshineng.com 2023-02-03 2023-10-30
HASH 83b4d96fc75f74bb589c28e8a9eddbbf 2023-02-03 2023-02-15
HASH 705ef00224f3f7b02e29f21eb6e10d02 2023-02-03 2023-02-15
HASH 873b2b0656ee9f6912390b5abc32b276 2023-02-03 2023-02-15
URL http://jooshineng.com/gnuboard4… 2023-02-03 2023-02-15
URL http://www.hydrotec.co.kr/bbs/i… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
URL http://www.hydrotec.co.kr/bbs/i… 2023-02-03 2023-02-15
URL http://ddim.co.kr/gnuboard4/adm… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
URL http://ddim.co.kr/gnuboard4/adm… 2023-02-03 2023-02-15
URL http://www.hydrotec.co.kr/bbs/i… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
DOMAIN ddim.co.kr 2023-02-03 2023-02-15
DOMAIN gdtech.kr 2023-02-03 2023-02-15
HASH 3cdf9f829ed03e1ac17b72b636d84d0b 2023-02-03 2023-02-03

Related Actors

Related Reports

« Back