Decryptor to celebrate Lunar New Year (Present From Kimsuky?!?!)
2020-01-23 • kino •
The Korean malware analysis links a Lunar New Year-themed sample to activity resembling an earlier Vietnamese event estimate lure associated with Kimsuky reporting. The executable contains a PDF decoy instead of an HWP document, drops and runs a malicious DLL, and uses encrypted strings that the author decodes with an IDA script. The source highlights a backdoor communicating with happy-new-year.esy.es and publishes representative hashes for the dropper and related payloads. The report is useful for tracking repeated lure formats, DLL-dropping behavior, string encryption, and infrastructure reuse around Kimsuky-attributed activity without overextending the attribution beyond the author’s cautious framing.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c315de8ac15b51163a3bc075063a58aa | 2020-01-23 | 2020-06-25 |
| HASH | da799d16aed24cf4f8ec62d5048afd1a | 2020-01-23 | 2020-02-06 |
| HASH | 6f715eb6815e9a44bf9a48d89c1b92f… | 2020-01-23 | 2020-01-23 |
| HASH | 5fdc8906a03ffd214e09816fdc58059a | 2020-01-23 | 2020-01-23 |
| HASH | c618645233b311e18e13322ffebec26… | 2020-01-23 | 2020-01-23 |
| HASH | de700699e8185497a82bb121fcc4cc6… | 2020-01-23 | 2020-01-23 |
| HASH | f7e04d06690cc6c2fa699c70b9f95ac… | 2020-01-23 | 2020-01-23 |
| HASH | 6d870937675b98355747ecfdf4768b2… | 2020-01-23 | 2020-01-23 |
| HASH | e2487b33a6510d6f51b8aa158a36c6c… | 2020-01-23 | 2020-01-23 |