APT 김수키(Kimsuky)에서 만든 악성코드-pay.bat(2024.11,27)

2024-12-05 Sakai Malware Created by APT Kimsuky - pay.bat (2024.11.27)

https://wezard4u.tistory.com/429348

Thumbnail for APT 김수키(Kimsuky)에서 만든 악성코드-pay.bat(2024.11,27)

A Kimsuky-linked BAT sample named pay.bat uses a hidden PowerShell launch with execution-policy bypass to decode and run an embedded Base64 command. The decoded script writes chrome.ps1 under the user's AppData directory, downloads and executes additional PowerShell content from Dropbox-hosted URLs, then removes the temporary downloaded scripts. It registers a hidden scheduled task named ChromeUpdateTaskMachine that starts after five minutes and repeats every 30 minutes, providing persistence for recurring script execution. The excerpt lists hashes for the BAT file and notes multiple vendor detections, including BAT/Kimsuky.O and downloader-oriented classifications, which can support detection and hunting for Kimsuky script staging behavior.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://dl.dropboxusercontent.c… 2024-12-05 2024-12-05
URL http://dl.dropboxusercontent.co… 2024-12-05 2024-12-05
URL http://dl.dropboxusercontent.co… 2024-12-05 2024-12-05
URL https://dl.dropboxusercontent.c… 2024-12-05 2024-12-05
URL https://dl.dropboxusercontent.c… 2024-12-05 2024-12-05
HASH 8e0eb0d36bfd4e28ec6a10acccf8997… 2024-12-01 2024-12-05
HASH fd02470c6cc4ceb5fad3589d02e5148… 2024-12-01 2024-12-05
HASH b262ac518c0114f414aaedbb4ef7c728 2024-12-01 2024-12-05

Related Actors

Related Reports

« Back