kimsuky's love is all around

2020-07-03 kino

https://sfkino.tistory.com/78

Thumbnail for kimsuky's love is all around

The source compares a Kimsuky HWP malware case with the earlier “KINU Expert Advisory Request.hwp” activity and shows that the exploit and shellcode remain largely the same while keys, C2, filenames, and mutexes changed. Shellcode injected into HimTrayIcon.exe decrypts and injects malware into userinit.exe, which steals system information and downloads additional payloads from lovelovelove.atwebpages.com paths. A later VMProtect-packed stage disguises itself under a misspelled Mozilla\Firefax directory, stores keylogging/process data in tader.wav, encrypts stolen information, and injects svchost.exe and iexplorer.exe for upload/download operations through a Daum email service. The report provides hashes, RC4 keys, mutex values, and the [email protected] account for hunting.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2020-07-03 2021-07-26
HASH 22bea8086d87fac45b85bea9e81ca142 2020-07-03 2021-05-01
HASH 8f8aa835e65998dd472d2c641aa82da5 2020-07-03 2021-05-01
HASH c73225f976100ab972934f31b61eabcc 2020-07-03 2021-05-01
URL http://lovelovelove.atwebpages.… 2020-07-03 2021-05-01
DOMAIN lovelovelove.atwebpages.com 2020-07-03 2021-05-01
DOMAIN clouds.scienceontheweb.net 2019-10-20 2021-05-01
HASH 2fd6ad80e0facbb2e9c46734035e190… 2020-07-03 2020-07-03
HASH 77f67e93c8bdea2ce9a66012b5ea2929 2020-07-03 2020-07-03
HASH 04f9579865c6611afd27fed6acaf858… 2020-07-03 2020-07-03
HASH 0ef06518dfce6641b2002c3c924a770… 2020-07-03 2020-07-03
HASH 3f64d8526190607541db64981e38255… 2020-07-03 2020-07-03
HASH b889a52be4e070fdebed48392574029… 2020-07-03 2020-07-03
HASH 55ae82c3d83e95b93aac9047b5ac35b… 2020-07-03 2020-07-03
HASH 55689d91df8435a5040abd591537bd6… 2020-07-03 2020-07-03
HASH 327865fa4009fc6a4d2ead8aa523eeff 2020-07-03 2020-07-03
HASH 70ec91d17b55980036351c70b2cbe3a0 2020-07-03 2020-07-03
HASH c6661195693d0f09d70c643f8719428… 2020-07-03 2020-07-03
HASH a869624bcd3fba754dec27fd7b04046… 2020-07-03 2020-07-03
HASH 0c457e1800dc1e516d97bef2c8f05c7… 2020-07-03 2020-07-03
HASH f9b8645bcb399e48b046bdd96f33b4b… 2020-07-03 2020-07-03
HASH 1db71af7956f90af9544c370a9dd357… 2020-07-03 2020-07-03
EMAIL [email protected] 2020-07-03 2020-07-03
URL http://clouds.scienceontheweb.n… 2020-07-03 2020-07-03
URL http://clouds.scienceontheweb.n… 2020-07-03 2020-07-03
URL http://lovelovelove.atwebpages.… 2020-07-03 2020-07-03

Related Actors

Related Reports

« Back