Kimsuky APT组织利用blogspot分发恶意载荷的攻击活动分析

2021-07-19 Qianxin Analysis of attack activities of Kimsuky APT organization using blogspot to distribute malicious payloads

https://ti.qianxin.com/blog/articles/Analysis-of-attack-activities-of-Kimsuky-APT-group-using-blogspot-to-distribute-malicious-payloads/

Thumbnail for Kimsuky APT组织利用blogspot分发恶意载荷的攻击活动分析

QiAnXin attributed several captured malicious document samples to Kimsuky, describing Korean fee-payment lures that displayed decoy content while inducing victims to enable malicious VBA. The core macro monitored text input before downloading Base64-encoded data from 1213rt.atwebpages.com, writing a VBS script as %AppData%\Microsoft\desktop.ini, and creating a startup shortcut named Internet Explorer.lnk for persistence. The VBS then retrieved an embedded payload from a Blogspot page such as kimshan600000.blogspot.com/2021/07/1.html, adding layers to the download chain and complicating attribution. The reported final backdoor behavior focused on system reconnaissance, including Microsoft Office Excel version collection and exfiltration to attacker infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0821884168a644f3c27176a52763acc9 2021-07-19 2021-09-01
HASH 95c92bcfc39ceafc1735f190a575c60c 2021-07-19 2021-09-01
DOMAIN wbg0909.scienceontheweb.net 2021-07-19 2021-09-01
URL http://alyssalove.getenjoyment.… 2021-06-09 2021-09-01
DOMAIN alyssalove.getenjoyment.net 2021-06-09 2021-09-01
HASH 8de75256d0e579416263cb3c61fc6c55 2021-07-19 2021-07-19
URL http://1213rt.atwebpages.com/co… 2021-07-19 2021-07-19
URL http://wbg0909.scienceontheweb.… 2021-07-19 2021-07-19
DOMAIN 1213rt.atwebpages.com 2021-07-19 2021-07-19

Related Actors

Related Reports

« Back