건강검진 안내 문서로 위장한 악성코드

2025-11-06 Logpresso Malware Disguised as a Health Checkup Notice Document

https://logpresso.com/en/blog/2025-11-06-healthcheckup-malware

Thumbnail for 건강검진 안내 문서로 위장한 악성코드

Logpresso assesses that a late-October 2025 attack using a health-check notice lure was conducted by the North Korea-linked Kimsuky group. The intrusion relied on an archive containing a JSE file disguised as a PDF, which displayed a benign document while decoding embedded PE data and loading it through rundll32.exe in the background. The malware contacted its C2 every minute, waited for staged responses such as “live” and “ok,” collected account, host, privilege, systeminfo, and ipconfig data, and uploaded the results with AES-128 and Base64 encoding. A later channel could retrieve an encrypted PE payload, decrypt it with RC4, load an additional DLL, and call a “hello” export, while infrastructure listed in the excerpt includes load.samework.o-r.kr and related o-r.kr/r-e.kr domains.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 485a886acdf832cce3fb902483e30f6… 2025-11-06 2026-02-03
HASH cf98f65f2b87eddca5e763e52b55d7f… 2025-11-06 2026-01-14
HASH 81e384471fcfa6752cb81ca1b7b9ee4… 2025-11-06 2026-01-14
HASH 2abff5efd1b8e2a938e2ec4ba105a8e… 2025-11-06 2026-01-14
DOMAIN mail.naverwork.r-e.kr 2025-11-06 2026-01-14
DOMAIN attach.skyline.r-e.kr 2025-11-06 2026-01-14
DOMAIN gwa.wooritg.o-r.kr 2025-11-06 2026-01-14
DOMAIN rwbcode.com 2025-11-06 2026-01-14
DOMAIN update.alzip.r-e.kr 2025-11-06 2026-01-14
DOMAIN image.secuwizvpn.r-e.kr 2025-11-06 2026-01-14
DOMAIN load.samework.o-r.kr 2025-11-06 2026-01-14
DOMAIN attach.skycloud.o-r.kr 2025-11-06 2026-01-14
DOMAIN mail.naverwork.o-r.kr 2025-11-06 2026-01-14
DOMAIN load.rwbcode.com 2025-11-06 2026-01-14
IPv4 162.220.11.202 2025-11-06 2026-01-14
URL http://load.rwbcode.com/index.p… 2025-11-06 2025-11-06
URL http://load.samework.o-r.kr/ind… 2025-11-06 2025-11-06

Related Actors

Related Reports

« Back