한글 문서 파일을 위장한 악성코드(Kimsuky)
2023-06-16 • Ahnlab • Malicious code disguised as a Korean document file (Kimsuky) •
AhnLab reports that Kimsuky-linked malware was distributed as a compressed archive containing a readme file and a .NET executable disguised as a Korean HWP document by using a document icon and padded filename spacing. When run, the dropper decodes an embedded Base64 PowerShell command, writes update.vbs under %APPDATA%, and displays a decoy error message using North Korean-style wording to reduce user suspicion. The decoded script downloads additional code from well-story.co.kr paths and executes scripts associated with user-information theft and keylogging, matching earlier Kimsuky malware behavior documented by AhnLab. Representative artifacts include MD5 hashes such as 8133c5f663f89b01b30a052749b5a988 and the URL hxxp://well-story.co[.]kr/adm/inc/js/list.php?query=1.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8133c5f663f89b01b30a052749b5a988 | 2023-06-16 | 2024-04-17 |
| DOMAIN | well-story.co.kr | 2023-06-16 | 2024-04-17 |
| HASH | 91029801f6f3a415392ccfee8226be67 | 2023-06-16 | 2023-08-16 |
| HASH | 73174c9d586531153a5793d050a394a8 | 2023-06-16 | 2023-08-16 |
| HASH | f05991652398406655a6a5eebe3e5f3a | 2023-06-16 | 2023-06-23 |
| HASH | ec1b518541228072eb75463ce15c7bce | 2023-06-16 | 2023-06-23 |
| URL | http://well-story.co.kr/adm/inc… | 2023-06-16 | 2023-06-23 |
| URL | http://well-story.co.kr/adm/inc… | 2023-06-16 | 2023-06-23 |
| URL | http://well-story.co.kr/adm/inc… | 2023-06-16 | 2023-06-23 |
| URL | http://well-story.co.kr/adm/inc… | 2023-06-16 | 2023-06-23 |
| URL | http://well-story.co.kr/adm/inc… | 2023-06-16 | 2023-06-23 |