항공우주공학 부분을 노리는 김수키(Kimsuky)만든 악성코드-강의의뢰서(2024.8.29)

2024-09-02 Sakai Malware Created by Kimsuky Targeting the Aerospace Engineering Sector - Lecture Request Form (2024.8.29)

http://wezard4u.tistory.com/429267

Thumbnail for 항공우주공학 부분을 노리는 김수키(Kimsuky)만든 악성코드-강의의뢰서(2024.8.29)

A Korean malware analysis describes a second Kimsuky-linked MSC sample using the same aerospace lecture request theme but a different hash, including SHA-256 83457462d1885acce9f4e46ad4053d050d3b0c7f3935b61f378e52f0eed5a68b. The MSC runs cmd.exe with a minimized window, downloads a decoy Word document named Grieco Kavanagh Passive Supporters.docx from rem.zoom-meeting.kro.kr, retrieves a payload as %appdata%\pest, writes it to %appdata%\pest.exe, and installs a scheduled task named TemporaryClearStatesesf to run every 58 minutes. It also downloads a manifest from the same 0829_pprb path, while the decoy document presents a lecture invitation about the space economy at a Seoul hotel. The source frames the activity as likely targeting aerospace engineering professors or companies to steal aerospace-related technology.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN zoom-meeting.kro.kr 2024-08-29 2025-03-07
DOMAIN rem.zoom-meeting.kro.kr 2024-08-29 2025-03-07
HASH bec918dd7c6f9d09f6cb4caeeee6fe03 2024-09-02 2024-10-04
HASH 10ec70cd8e388e2640364ee95e432c2… 2024-09-02 2024-09-02
HASH 83457462d1885acce9f4e46ad4053d0… 2024-09-02 2024-09-02
URL http://rem.zoom-meeting.kro.kr/… 2024-09-02 2024-09-02
URL http://rem.zoom-meeting.kro.kr/… 2024-08-29 2024-09-02
URL http://rem.zoom-meeting.kro.kr/… 2024-08-29 2024-09-02
URL http://rem.zoom-meeting.kro.kr/… 2024-08-29 2024-09-02
DOMAIN g.kro.kr 2024-08-29 2024-09-02

Related Actors

Related Reports

« Back