항공우주공학 부분을 노리는 김수키(Kimsuky)만든 악성코드-강의의뢰서(2024.8.29)
2024-09-02 • Sakai • Malware Created by Kimsuky Targeting the Aerospace Engineering Sector - Lecture Request Form (2024.8.29) •
A Korean malware analysis describes a second Kimsuky-linked MSC sample using the same aerospace lecture request theme but a different hash, including SHA-256 83457462d1885acce9f4e46ad4053d050d3b0c7f3935b61f378e52f0eed5a68b. The MSC runs cmd.exe with a minimized window, downloads a decoy Word document named Grieco Kavanagh Passive Supporters.docx from rem.zoom-meeting.kro.kr, retrieves a payload as %appdata%\pest, writes it to %appdata%\pest.exe, and installs a scheduled task named TemporaryClearStatesesf to run every 58 minutes. It also downloads a manifest from the same 0829_pprb path, while the decoy document presents a lecture invitation about the space economy at a Seoul hotel. The source frames the activity as likely targeting aerospace engineering professors or companies to steal aerospace-related technology.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | zoom-meeting.kro.kr | 2024-08-29 | 2025-03-07 |
| DOMAIN | rem.zoom-meeting.kro.kr | 2024-08-29 | 2025-03-07 |
| HASH | bec918dd7c6f9d09f6cb4caeeee6fe03 | 2024-09-02 | 2024-10-04 |
| HASH | 10ec70cd8e388e2640364ee95e432c2… | 2024-09-02 | 2024-09-02 |
| HASH | 83457462d1885acce9f4e46ad4053d0… | 2024-09-02 | 2024-09-02 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-09-02 | 2024-09-02 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-08-29 | 2024-09-02 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-08-29 | 2024-09-02 |
| URL | http://rem.zoom-meeting.kro.kr/… | 2024-08-29 | 2024-09-02 |
| DOMAIN | g.kro.kr | 2024-08-29 | 2024-09-02 |