주중대사관 을 타겟으로 추측이 되는 Kimsuky(김수키) 만든 악성코드-202404주중대사관 정책간담회.rar(2024.3.29)

2024-04-03 Sakai Malware Created by Kimsuky Suspected of Targeting the Chinese Embassy - 202404 Chinese Embassy Policy Meeting.rar (2024.3.29)

http://wezard4u.tistory.com/6776

Thumbnail for 주중대사관 을 타겟으로 추측이 되는 Kimsuky(김수키) 만든 악성코드-202404주중대사관 정책간담회.rar(2024.3.29)

A Kimsuky-attributed RAR archive used a Korean Embassy in China policy-meeting theme to lure likely embassy or policy-related personnel into running a shortcut file disguised with an HWP-style document icon. The LNK launches hidden PowerShell, extracts embedded content, deletes the original shortcut, contacts Dropbox via API credentials, downloads /step5/ps.bin, AES-decrypts it with a hardcoded password, and executes the resulting script. The lure document impersonates a private Korea-China and North Korea-China security policy meeting plan, supporting the social-engineering angle against diplomatic or government-linked targets. The excerpt provides file hashes for the RAR, LNK, and generated artifact, a Google Drive delivery URL, a Dropbox download path, and antivirus detections including LNK/Kimsuky and Powecod-style behavior.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a4bd6d00abbd79ab00161ff538cfe703 2024-04-03 2024-04-17
HASH 075d7249d09f14cbf0a4ffcb077c775… 2024-04-03 2024-04-10
HASH fe156159a26f8b7c140db61dd8b136e… 2024-04-03 2024-04-10
HASH 32e739ea04e2afc0f73d54f78f08cc3… 2024-04-03 2024-04-03
HASH 724bf81c0a9adb3ffe6b03a21f7cab09 2024-04-03 2024-04-03
HASH bfcb7e6e5048c19020e26be236d7071… 2024-04-03 2024-04-03
HASH a20aa6632048852a2e40cd5a6cfebfda 2024-04-03 2024-04-03
HASH e9a73243f0fbd158ad0113753c3b289… 2024-04-03 2024-04-03
HASH fc5f07699655fd283b9c525233f4c9a… 2024-04-03 2024-04-03
EMAIL [email protected] 2024-04-03 2024-04-03
URL https://content.dropboxapi.com/… 2024-04-03 2024-04-03
DOMAIN system.io.me 2024-04-03 2024-04-03
URL https://api.dropboxapi.com/oaut… 2024-03-28 2024-04-03

Related Actors

Related Reports

« Back