Kimsuky VBS RAT 악성코드 분석 보고서

2024-08-22 Nurilab Analysis Report on Kimsuky VBS RAT Malware

https://blog.naver.com/nurilab1/223556640169

Nurilab analyzed a VBS RAT script assessed as a BabyShark payload from Kimsuky activity against South Korean university professors in July 2024. The infection path used spearphishing to Gmail and Daum accounts, fake Naver or university portal login pages for credential theft, and a Google Drive hosted Asan Institute forum PDF to trigger BabyShark execution. The script writes decoded PowerShell and VBS components under AppData and the Startup folder to persist across logins. Its command set can enumerate drives and files, download and upload paths, delete or rename content, create directories, execute files, compress data, and exfiltrate information to attacker infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8c44750ad8bbca79db2973c24e87bb92 2024-08-22 2024-08-22
HASH 91c86a4350938b129cfffea60502e1b… 2024-08-22 2024-08-22
HASH fc840ba6890b63ff57d788e4ed42ca8… 2024-08-22 2024-08-22
HASH 58d97883bc932dae82b3e14de3cceb57 2024-08-22 2024-08-22
HASH 7160b07ddebad54e15efc03d6e1cdc0… 2024-08-22 2024-08-22
HASH 800e14f182c21af59b0fc777bdfe9f6… 2024-08-22 2024-08-22
HASH ed51b6bf6b004c120cb677a016d6ce4… 2024-08-22 2024-08-22
HASH 2179e1c9831bec7c15f0be0af2537fe3 2024-08-22 2024-08-22
HASH 45125b56767b5bd4d93b5e303b3a2b9… 2024-08-22 2024-08-22
IPv4 5.61.59.53 2023-10-16 2024-08-22

Related Actors

Related Reports

« Back