Kimsuky APT组织利用blogspot分发恶意载荷的攻击活动分析
2021-07-19 • Qianxin • Analysis of attack activities of Kimsuky APT organization using blogspot to distribute malicious payloads •
QiAnXin attributed several captured malicious document samples to Kimsuky, describing Korean fee-payment lures that displayed decoy content while inducing victims to enable malicious VBA. The core macro monitored text input before downloading Base64-encoded data from 1213rt.atwebpages.com, writing a VBS script as %AppData%\Microsoft\desktop.ini, and creating a startup shortcut named Internet Explorer.lnk for persistence. The VBS then retrieved an embedded payload from a Blogspot page such as kimshan600000.blogspot.com/2021/07/1.html, adding layers to the download chain and complicating attribution. The reported final backdoor behavior focused on system reconnaissance, including Microsoft Office Excel version collection and exfiltration to attacker infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0821884168a644f3c27176a52763acc9 | 2021-07-19 | 2021-09-01 |
| HASH | 95c92bcfc39ceafc1735f190a575c60c | 2021-07-19 | 2021-09-01 |
| DOMAIN | wbg0909.scienceontheweb.net | 2021-07-19 | 2021-09-01 |
| URL | http://alyssalove.getenjoyment.… | 2021-06-09 | 2021-09-01 |
| DOMAIN | alyssalove.getenjoyment.net | 2021-06-09 | 2021-09-01 |
| HASH | 8de75256d0e579416263cb3c61fc6c55 | 2021-07-19 | 2021-07-19 |
| URL | http://1213rt.atwebpages.com/co… | 2021-07-19 | 2021-07-19 |
| URL | http://wbg0909.scienceontheweb.… | 2021-07-19 | 2021-07-19 |
| DOMAIN | 1213rt.atwebpages.com | 2021-07-19 | 2021-07-19 |