Kimsuky(김수키)에서 만든 자유 아시아 방송으로 위장 해서 특정 북한 인권운동가 노린 악성코드-log_processlist.ps1(2024.12.02)
2024-12-26 • Sakai • Malware Created by Kimsuky Disguised as Radio Free Asia and Targeting a Specific North Korean Human Rights Activist - log_processlist.ps1 (2024.12.02) •
The report analyzes a Kimsuky-attributed PowerShell malware case, log_processlist.ps1, distributed from a site impersonating Radio Free Asia and aimed at a specific North Korean human-rights activist. The script used Dropbox API credentials to obtain an OAuth token, collected host information including network IPs, running processes, and local disk details, and staged the results in temporary files. It then compressed the collected process-list data for exfiltration to attacker-controlled Dropbox storage and removed local temporary artifacts such as VBS, ZIP, and text files to reduce forensic traces.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a26fbfa800e36e43f6e0e5ed7a9dcad… | 2024-12-26 | 2024-12-26 |
| HASH | 77d5f545661717e31e99fb0880510b0… | 2024-12-26 | 2024-12-26 |
| HASH | d38a6f924abf59eac2f962dcbff6703c | 2024-12-26 | 2024-12-26 |
| URL | http://bureopen.store/1127 | 2024-12-26 | 2024-12-26 |
| DOMAIN | bureopen.store | 2024-12-26 | 2024-12-26 |