한국 관광을 핑계로 러시아 인들을 타겟을 하고 추정 되는 김수키(Kimsuky)만든 악성코드-241007.lnk(2024.10.14)
2024-10-17 • Sakai • Suspected Kimsuky Malware Targeting Russian Speakers with a Korean Tourism Lure •
A suspected Kimsuky LNK sample named 241007.lnk uses a Korean tourism and travel-study lure aimed at Russian-speaking users. The shortcut executes PowerShell, searches for a matching large .lnk file, extracts embedded data into a PDF decoy, and writes a winboot.bat payload under the public Libraries path. It creates a scheduled task named NotepadPlusAutoUpdate to run the batch file every six minutes, supporting persistence through a benign-looking updater name. The batch logic uses curl to download reboot234.bat from hxxps://contactcenter(.)mobilo(.)mx/vicidial/ploticus/mobile(.)php?choko=GYHASOLS, while published hashes and vendor detections support triage of the LNK dropper.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7eb7d0133965022ad362132782da9d15 | 2024-10-17 | 2024-10-17 |
| HASH | 564b9c9dac942c1284ab565607997b7… | 2024-10-17 | 2024-10-17 |
| HASH | 2a9524821533e3285e9271706c67302… | 2024-10-17 | 2024-10-17 |
| URL | https://contactcenter.mobilo.mx… | 2024-10-17 | 2024-10-17 |
| DOMAIN | contactcenter.mobilo.mx | 2024-10-17 | 2024-10-17 |