한국 관광을 핑계로 러시아 인들을 타겟을 하고 추정 되는 김수키(Kimsuky)만든 악성코드-241007.lnk(2024.10.14)

2024-10-17 Sakai Suspected Kimsuky Malware Targeting Russian Speakers with a Korean Tourism Lure

http://wezard4u.tistory.com/429304

Thumbnail for 한국 관광을 핑계로 러시아 인들을 타겟을 하고 추정 되는 김수키(Kimsuky)만든 악성코드-241007.lnk(2024.10.14)

A suspected Kimsuky LNK sample named 241007.lnk uses a Korean tourism and travel-study lure aimed at Russian-speaking users. The shortcut executes PowerShell, searches for a matching large .lnk file, extracts embedded data into a PDF decoy, and writes a winboot.bat payload under the public Libraries path. It creates a scheduled task named NotepadPlusAutoUpdate to run the batch file every six minutes, supporting persistence through a benign-looking updater name. The batch logic uses curl to download reboot234.bat from hxxps://contactcenter(.)mobilo(.)mx/vicidial/ploticus/mobile(.)php?choko=GYHASOLS, while published hashes and vendor detections support triage of the LNK dropper.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7eb7d0133965022ad362132782da9d15 2024-10-17 2024-10-17
HASH 564b9c9dac942c1284ab565607997b7… 2024-10-17 2024-10-17
HASH 2a9524821533e3285e9271706c67302… 2024-10-17 2024-10-17
URL https://contactcenter.mobilo.mx… 2024-10-17 2024-10-17
DOMAIN contactcenter.mobilo.mx 2024-10-17 2024-10-17

Related Actors

Related Reports

« Back