Kimsuky(김수키)에서 만든 자유 아시아 방송으로 위장 해서 특정 북한 인권운동가 노린 악성코드-log_processlist.ps1(2024.12.02)

2024-12-26 Sakai Malware Created by Kimsuky Disguised as Radio Free Asia and Targeting a Specific North Korean Human Rights Activist - log_processlist.ps1 (2024.12.02)

https://wezard4u.tistory.com/429365

Thumbnail for Kimsuky(김수키)에서 만든 자유 아시아 방송으로 위장 해서 특정 북한 인권운동가 노린 악성코드-log_processlist.ps1(2024.12.02)

The report analyzes a Kimsuky-attributed PowerShell malware case, log_processlist.ps1, distributed from a site impersonating Radio Free Asia and aimed at a specific North Korean human-rights activist. The script used Dropbox API credentials to obtain an OAuth token, collected host information including network IPs, running processes, and local disk details, and staged the results in temporary files. It then compressed the collected process-list data for exfiltration to attacker-controlled Dropbox storage and removed local temporary artifacts such as VBS, ZIP, and text files to reduce forensic traces.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a26fbfa800e36e43f6e0e5ed7a9dcad… 2024-12-26 2024-12-26
HASH 77d5f545661717e31e99fb0880510b0… 2024-12-26 2024-12-26
HASH d38a6f924abf59eac2f962dcbff6703c 2024-12-26 2024-12-26
URL http://bureopen.store/1127 2024-12-26 2024-12-26
DOMAIN bureopen.store 2024-12-26 2024-12-26

Related Actors

Related Reports

« Back