주중대사관 을 타겟으로 추측이 되는 Kimsuky(김수키) 만든 악성코드-202404주중대사관 정책간담회.rar(2024.3.29)
2024-04-03 • Sakai • Malware Created by Kimsuky Suspected of Targeting the Chinese Embassy - 202404 Chinese Embassy Policy Meeting.rar (2024.3.29) •
A Kimsuky-attributed RAR archive used a Korean Embassy in China policy-meeting theme to lure likely embassy or policy-related personnel into running a shortcut file disguised with an HWP-style document icon. The LNK launches hidden PowerShell, extracts embedded content, deletes the original shortcut, contacts Dropbox via API credentials, downloads /step5/ps.bin, AES-decrypts it with a hardcoded password, and executes the resulting script. The lure document impersonates a private Korea-China and North Korea-China security policy meeting plan, supporting the social-engineering angle against diplomatic or government-linked targets. The excerpt provides file hashes for the RAR, LNK, and generated artifact, a Google Drive delivery URL, a Dropbox download path, and antivirus detections including LNK/Kimsuky and Powecod-style behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a4bd6d00abbd79ab00161ff538cfe703 | 2024-04-03 | 2024-04-17 |
| HASH | 075d7249d09f14cbf0a4ffcb077c775… | 2024-04-03 | 2024-04-10 |
| HASH | fe156159a26f8b7c140db61dd8b136e… | 2024-04-03 | 2024-04-10 |
| HASH | 32e739ea04e2afc0f73d54f78f08cc3… | 2024-04-03 | 2024-04-03 |
| HASH | 724bf81c0a9adb3ffe6b03a21f7cab09 | 2024-04-03 | 2024-04-03 |
| HASH | bfcb7e6e5048c19020e26be236d7071… | 2024-04-03 | 2024-04-03 |
| HASH | a20aa6632048852a2e40cd5a6cfebfda | 2024-04-03 | 2024-04-03 |
| HASH | e9a73243f0fbd158ad0113753c3b289… | 2024-04-03 | 2024-04-03 |
| HASH | fc5f07699655fd283b9c525233f4c9a… | 2024-04-03 | 2024-04-03 |
| [email protected] | 2024-04-03 | 2024-04-03 | |
| URL | https://content.dropboxapi.com/… | 2024-04-03 | 2024-04-03 |
| DOMAIN | system.io.me | 2024-04-03 | 2024-04-03 |
| URL | https://api.dropboxapi.com/oaut… | 2024-03-28 | 2024-04-03 |