Kimsuky 3
2024-03-12 • somedieyoung ZZ •
The source analyzes a Kimsuky sample named like a Korean software security checklist for developers, using a double extension to make a VBScript look like an Excel macro file. The VBScript creates shell and file-system objects, writes large Base64 payloads under ProgramData or the Windows root, decodes one payload with certutil, launches the resulting decoy file, and runs a batch command that XOR-decodes another payload. It then executes the decoded component through regsvr32 and deletes the original script, making the lure useful for detecting developer-themed phishing, script obfuscation, Base64 staging, and living-off-the-land execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | kimsuky_VBS_script | 2024-03-12 | 2024-03-12 |
| DOMAIN | tes.co | 2024-03-12 | 2024-03-12 |
| HASH | 39a61c4d9d25c8ed1b38b1a51a8ef0b… | 2023-02-09 | 2024-03-12 |
| HASH | db18e23bebb8581ba5670201cea98cc… | 2023-02-09 | 2024-03-12 |
| HASH | 12539ac37a81cc2e19338a67d237f833 | 2022-09-14 | 2024-03-12 |
| URL | http://qwert.mine.bz/index.php | 2022-09-14 | 2024-03-12 |
| DOMAIN | qwert.mine.bz | 2022-09-14 | 2024-03-12 |
| IPv4 | 216.189.154.6 | 2022-08-25 | 2024-03-12 |