Kimsucky Apt Analysis
2024-03-02 • somedieyoung ZZ •
https://somedieyoungzz.github.io/posts/kimsucky-apt-analysis/
The analysis examines a Kimsuky-linked malicious Word document that uses social engineering to make the victim enable macros and then executes PowerShell from a temporary file. The macro writes and runs code from C:\Windows\Temp\bobo.txt, which downloads flower01.ps1 from mybobo.mygamesonline.org and establishes persistence under the current user's Run key using an Alzipupdate value. The PowerShell script gathers recent-file, program directory, system, and process information into a file named flower01.hwp under the user's roaming profile, then uploads collected data to the command-and-control server. It also includes decoding logic and download functionality for commands from the C2, supporting remote execution, file upload, file download, persistence, and system reconnaissance. The post frames this activity within Kimsuky's long-running espionage targeting of South Korean government, research, academic, and private-sector entities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 07d0be79be38ecb8c7b1c80ab0bd8344 | 2024-03-02 | 2024-03-02 |
| HASH | 1fcd9892532813a27537f4e1a1c21ec… | 2020-03-20 | 2024-03-02 |
| URL | http://mybobo.mygamesonline.org… | 2020-03-20 | 2024-03-02 |
| DOMAIN | mybobo.mygamesonline.org | 2020-03-20 | 2024-03-02 |
| IPv4 | 185.176.43.82 | 2020-03-20 | 2024-03-02 |