한글 문서 파일을 위장한 악성코드(Kimsuky)

2023-06-16 Ahnlab Malicious code disguised as a Korean document file (Kimsuky)

https://asec.ahnlab.com/ko/54473/

Thumbnail for 한글 문서 파일을 위장한 악성코드(Kimsuky)

AhnLab reports that Kimsuky-linked malware was distributed as a compressed archive containing a readme file and a .NET executable disguised as a Korean HWP document by using a document icon and padded filename spacing. When run, the dropper decodes an embedded Base64 PowerShell command, writes update.vbs under %APPDATA%, and displays a decoy error message using North Korean-style wording to reduce user suspicion. The decoded script downloads additional code from well-story.co.kr paths and executes scripts associated with user-information theft and keylogging, matching earlier Kimsuky malware behavior documented by AhnLab. Representative artifacts include MD5 hashes such as 8133c5f663f89b01b30a052749b5a988 and the URL hxxp://well-story.co[.]kr/adm/inc/js/list.php?query=1.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8133c5f663f89b01b30a052749b5a988 2023-06-16 2024-04-17
DOMAIN well-story.co.kr 2023-06-16 2024-04-17
HASH 91029801f6f3a415392ccfee8226be67 2023-06-16 2023-08-16
HASH 73174c9d586531153a5793d050a394a8 2023-06-16 2023-08-16
HASH f05991652398406655a6a5eebe3e5f3a 2023-06-16 2023-06-23
HASH ec1b518541228072eb75463ce15c7bce 2023-06-16 2023-06-23
URL http://well-story.co.kr/adm/inc… 2023-06-16 2023-06-23
URL http://well-story.co.kr/adm/inc… 2023-06-16 2023-06-23
URL http://well-story.co.kr/adm/inc… 2023-06-16 2023-06-23
URL http://well-story.co.kr/adm/inc… 2023-06-16 2023-06-23
URL http://well-story.co.kr/adm/inc… 2023-06-16 2023-06-23

Related Actors

Related Reports

« Back