Kimsuky武器库更新:利用新冠疫情为诱饵针对韩国地区的攻击活动分析
2021-10-12 • Qianxin • Kimsuky arsenal update: analysis of attacks targeting South Korea using the COVID-19 epidemic as bait •
QiAnXin analyzed a Kimsuky-attributed attack against South Korean targets that used COVID-19 response material tied to a local land-management office as the lure. The malware arrived as a PIF executable masquerading as a PDF, acting as a loader that decrypted API strings, wrote both decoy and payload files under C:\ProgramData\, and launched the next stage with a fixed parameter. The payload copied itself as smss.exe under a system32-named folder, configured registry-based startup persistence, and included a file-deletion routine that overwrote, renamed, and removed target files. QiAnXin linked the activity to Kimsuky through malware analysis and infrastructure overlap, including reuse of IP address 216.189.149.78 and the domain movie.youtoboo.kro.kr.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 946f787c129bf469298aa881fb0843f4 | 2021-10-12 | 2021-10-12 |
| HASH | e33a34fa0e0696f6eae4feba11873f56 | 2021-10-12 | 2021-10-12 |
| DOMAIN | movie.youtoboo.kro.kr | 2021-10-12 | 2021-10-12 |
| IPv4 | 216.189.149.78 | 2021-10-12 | 2021-10-12 |