DropBox를 이용한 Kimsuky 악성코드
2024-03-22 • Hauri • ( Document No : DT-20240322-001 ) •
https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=60
Attachments
Hauri reports that Kimsuky has been distributing malicious Windows shortcut files since December 2023 against security-related targets and cryptocurrency investors, with a focus on information theft. The LNK execution chain runs PowerShell, uses Dropbox refresh and access tokens to retrieve encrypted payloads such as /step1/ps.bin, decrypts and executes staged scripts, and establishes persistence through scheduled tasks that run every 10 minutes. The malware collects process and service lists, system information, firewall settings, installed antivirus products, and file listings from user folders before AES-encrypting the results and uploading them to attacker-controlled Dropbox paths. Later stages include keylogging, browser credential theft, Google Drive-hosted payload retrieval, and UltraVNC deployment with a firewall rule allowing port 5900 for remote control. The report provides multiple MD5 hashes for LNK lures and related files, making it useful for tracking Kimsuky cloud-storage-based delivery and post-compromise collection tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | eb08ab3854168c834ab154facfe695a3 | 2024-03-22 | 2024-04-17 |
| HASH | 1e66ac680d0edfe18d97b89e46c7e82e | 2024-03-22 | 2024-04-17 |
| HASH | c700195f61635b9a6fb1ee4359b91940 | 2024-03-22 | 2024-04-17 |
| HASH | fcdcc6c56ae43f7a78413cc5204e9314 | 2024-01-30 | 2024-04-17 |
| HASH | 32519b46b55792084240f850e0c94298 | 2024-01-30 | 2024-04-17 |
| URL | https://hyojadong.kr/js/slick/d… | 2024-01-30 | 2024-03-28 |
| DOMAIN | hyojadong.kr | 2024-01-30 | 2024-03-28 |
| HASH | c47675700b20537374c86e7a5426f848 | 2024-03-22 | 2024-03-22 |
| HASH | 886535bbe925890a01f49f49f49fee40 | 2024-03-22 | 2024-03-22 |