APT 김수키(Kimsuky)에서 만든 악성코드-pay.bat(2024.11,27)
2024-12-05 • Sakai • Malware Created by APT Kimsuky - pay.bat (2024.11.27) •
A Kimsuky-linked BAT sample named pay.bat uses a hidden PowerShell launch with execution-policy bypass to decode and run an embedded Base64 command. The decoded script writes chrome.ps1 under the user's AppData directory, downloads and executes additional PowerShell content from Dropbox-hosted URLs, then removes the temporary downloaded scripts. It registers a hidden scheduled task named ChromeUpdateTaskMachine that starts after five minutes and repeats every 30 minutes, providing persistence for recurring script execution. The excerpt lists hashes for the BAT file and notes multiple vendor detections, including BAT/Kimsuky.O and downloader-oriented classifications, which can support detection and hunting for Kimsuky script staging behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://dl.dropboxusercontent.c… | 2024-12-05 | 2024-12-05 |
| URL | http://dl.dropboxusercontent.co… | 2024-12-05 | 2024-12-05 |
| URL | http://dl.dropboxusercontent.co… | 2024-12-05 | 2024-12-05 |
| URL | https://dl.dropboxusercontent.c… | 2024-12-05 | 2024-12-05 |
| URL | https://dl.dropboxusercontent.c… | 2024-12-05 | 2024-12-05 |
| HASH | 8e0eb0d36bfd4e28ec6a10acccf8997… | 2024-12-01 | 2024-12-05 |
| HASH | fd02470c6cc4ceb5fad3589d02e5148… | 2024-12-01 | 2024-12-05 |
| HASH | b262ac518c0114f414aaedbb4ef7c728 | 2024-12-01 | 2024-12-05 |