Kimsuky VBS RAT 악성코드 분석 보고서
2024-08-22 • Nurilab • Analysis Report on Kimsuky VBS RAT Malware •
Nurilab analyzed a VBS RAT script assessed as a BabyShark payload from Kimsuky activity against South Korean university professors in July 2024. The infection path used spearphishing to Gmail and Daum accounts, fake Naver or university portal login pages for credential theft, and a Google Drive hosted Asan Institute forum PDF to trigger BabyShark execution. The script writes decoded PowerShell and VBS components under AppData and the Startup folder to persist across logins. Its command set can enumerate drives and files, download and upload paths, delete or rename content, create directories, execute files, compress data, and exfiltrate information to attacker infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8c44750ad8bbca79db2973c24e87bb92 | 2024-08-22 | 2024-08-22 |
| HASH | 91c86a4350938b129cfffea60502e1b… | 2024-08-22 | 2024-08-22 |
| HASH | fc840ba6890b63ff57d788e4ed42ca8… | 2024-08-22 | 2024-08-22 |
| HASH | 58d97883bc932dae82b3e14de3cceb57 | 2024-08-22 | 2024-08-22 |
| HASH | 7160b07ddebad54e15efc03d6e1cdc0… | 2024-08-22 | 2024-08-22 |
| HASH | 800e14f182c21af59b0fc777bdfe9f6… | 2024-08-22 | 2024-08-22 |
| HASH | ed51b6bf6b004c120cb677a016d6ce4… | 2024-08-22 | 2024-08-22 |
| HASH | 2179e1c9831bec7c15f0be0af2537fe3 | 2024-08-22 | 2024-08-22 |
| HASH | 45125b56767b5bd4d93b5e303b3a2b9… | 2024-08-22 | 2024-08-22 |
| IPv4 | 5.61.59.53 | 2023-10-16 | 2024-08-22 |