Decryptor to celebrate Lunar New Year (Present From Kimsuky?!?!)

2020-01-23 kino

https://sfkino.tistory.com/77

The Korean malware analysis links a Lunar New Year-themed sample to activity resembling an earlier Vietnamese event estimate lure associated with Kimsuky reporting. The executable contains a PDF decoy instead of an HWP document, drops and runs a malicious DLL, and uses encrypted strings that the author decodes with an IDA script. The source highlights a backdoor communicating with happy-new-year.esy.es and publishes representative hashes for the dropper and related payloads. The report is useful for tracking repeated lure formats, DLL-dropping behavior, string encryption, and infrastructure reuse around Kimsuky-attributed activity without overextending the attribution beyond the author’s cautious framing.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c315de8ac15b51163a3bc075063a58aa 2020-01-23 2020-06-25
HASH da799d16aed24cf4f8ec62d5048afd1a 2020-01-23 2020-02-06
HASH 6f715eb6815e9a44bf9a48d89c1b92f… 2020-01-23 2020-01-23
HASH 5fdc8906a03ffd214e09816fdc58059a 2020-01-23 2020-01-23
HASH c618645233b311e18e13322ffebec26… 2020-01-23 2020-01-23
HASH de700699e8185497a82bb121fcc4cc6… 2020-01-23 2020-01-23
HASH f7e04d06690cc6c2fa699c70b9f95ac… 2020-01-23 2020-01-23
HASH 6d870937675b98355747ecfdf4768b2… 2020-01-23 2020-01-23
HASH e2487b33a6510d6f51b8aa158a36c6c… 2020-01-23 2020-01-23

Related Actors

Related Reports

« Back