Kimsuky 3

2024-03-12 somedieyoung ZZ

https://somedieyoungzz.github.io/posts/kimsuky-3/

The source analyzes a Kimsuky sample named like a Korean software security checklist for developers, using a double extension to make a VBScript look like an Excel macro file. The VBScript creates shell and file-system objects, writes large Base64 payloads under ProgramData or the Windows root, decodes one payload with certutil, launches the resulting decoy file, and runs a batch command that XOR-decodes another payload. It then executes the decoded component through regsvr32 and deletes the original script, making the lure useful for detecting developer-themed phishing, script obfuscation, Base64 staging, and living-off-the-land execution.

Indicators of Compromise

Type Value First Seen Last Seen
YARA kimsuky_VBS_script 2024-03-12 2024-03-12
DOMAIN tes.co 2024-03-12 2024-03-12
HASH 39a61c4d9d25c8ed1b38b1a51a8ef0b… 2023-02-09 2024-03-12
HASH db18e23bebb8581ba5670201cea98cc… 2023-02-09 2024-03-12
HASH 12539ac37a81cc2e19338a67d237f833 2022-09-14 2024-03-12
URL http://qwert.mine.bz/index.php 2022-09-14 2024-03-12
DOMAIN qwert.mine.bz 2022-09-14 2024-03-12
IPv4 216.189.154.6 2022-08-25 2024-03-12

Related Actors

Related Reports

« Back