2024-09-10 KIMSUKY (North Korean APT) Sample (Sakai @sakaijjan - Terms and Conditions.msc)
2024-09-10 • Contagio •
https://contagiodump.blogspot.com/2024/09/2024-09-10-kimsuky-north-korean-apt.html
A Kimsuky sample named Terms and conditions.msc embeds PowerShell commands that run hidden from the user and retrieve additional content from hxxps://0x0(.)st/Xyl7(.)txt. The script uses Invoke-Expression and Invoke-WebRequest, decodes hexadecimal data into a byte array, saves it under a misleading MP3 filename in Public Documents, then renames it to an executable and launches it through conhost.exe. The infection chain emphasizes camouflage and stealth through a benign-looking Microsoft Management Console file, hidden PowerShell execution, file extension masquerading, and background process execution. The excerpt lists MD5, SHA-1, and SHA-256 hashes for the sample, supporting detection and correlation for Kimsuky tradecraft using lightweight staged payload delivery.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cea22277e0d7fe38a3755bdb8baa9fe… | 2024-09-10 | 2024-09-10 |
| HASH | f4895809cb38fa1f225340e99c05e47… | 2024-09-10 | 2024-09-10 |
| HASH | 81d224649328a61c899be9403d1de92d | 2024-09-10 | 2024-09-10 |
| URL | https://0x0.st/Xyl7.txt | 2024-09-10 | 2024-09-10 |
| DOMAIN | 0x0.st | 2024-08-19 | 2024-09-10 |