2024-09-10 KIMSUKY (North Korean APT) Sample (Sakai @sakaijjan - Terms and Conditions.msc)

2024-09-10 Contagio

https://contagiodump.blogspot.com/2024/09/2024-09-10-kimsuky-north-korean-apt.html

Thumbnail for 2024-09-10 KIMSUKY (North Korean APT) Sample (Sakai @sakaijjan - Terms and Conditions.msc)

A Kimsuky sample named Terms and conditions.msc embeds PowerShell commands that run hidden from the user and retrieve additional content from hxxps://0x0(.)st/Xyl7(.)txt. The script uses Invoke-Expression and Invoke-WebRequest, decodes hexadecimal data into a byte array, saves it under a misleading MP3 filename in Public Documents, then renames it to an executable and launches it through conhost.exe. The infection chain emphasizes camouflage and stealth through a benign-looking Microsoft Management Console file, hidden PowerShell execution, file extension masquerading, and background process execution. The excerpt lists MD5, SHA-1, and SHA-256 hashes for the sample, supporting detection and correlation for Kimsuky tradecraft using lightweight staged payload delivery.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cea22277e0d7fe38a3755bdb8baa9fe… 2024-09-10 2024-09-10
HASH f4895809cb38fa1f225340e99c05e47… 2024-09-10 2024-09-10
HASH 81d224649328a61c899be9403d1de92d 2024-09-10 2024-09-10
URL https://0x0.st/Xyl7.txt 2024-09-10 2024-09-10
DOMAIN 0x0.st 2024-08-19 2024-09-10

Related Actors

Related Reports

« Back