김수키(Kimsuky)암호화폐 거래소 업비트 사칭 악성코드-Upbit_20240916 docx lnk(2024.9.17)

2024-09-20 Sakai Kimsuky malware impersonating the Upbit cryptocurrency exchange through DOCX and LNK lures

https://wezard4u.tistory.com/429281

Thumbnail for 김수키(Kimsuky)암호화폐 거래소 업비트 사칭 악성코드-Upbit_20240916 docx lnk(2024.9.17)

Kimsuky is linked in the excerpt to a malicious LNK file disguised as an Upbit cryptocurrency-exchange document, with SHA-256 41cf6298a41c27357ee5f70d8cd1c0bd48698fc30c4255fad6a91798286e5229. The shortcut uses mshta.exe to launch obfuscated JavaScript and PowerShell, bypass execution policy, connect to 64.49.14.181:8014, decode a Base64 ZIP into ProgramData, extract it, and run s.vbs. Follow-on script content creates scheduled-task and Run-key persistence, opens a decoy DOCX, and executes PowerShell from temporary files. A later payload establishes TCP command handling against 64.49.14.181 on port 7032, writes received commands to tmps2.ps1, executes them with PowerShell, and deletes the temporary script, giving defenders concrete lure, persistence, C2, and hash indicators to hunt.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 64.49.14.181 2024-09-17 2024-09-26
HASH 6564c5e2e6193e6a947f00881a92c1a… 2024-09-20 2024-09-20
HASH 963af57641c094df6b5656552daaafd… 2024-09-20 2024-09-20
HASH ea96a61215ac44e295a19d3ede58e9b… 2024-09-20 2024-09-20
HASH 40756e44f5721dbb8d17bc538336d15… 2024-09-20 2024-09-20
HASH c4aba442d881cfa112fe3a6b1d2381b… 2024-09-17 2024-09-20
HASH 41cf6298a41c27357ee5f70d8cd1c0b… 2024-09-17 2024-09-20

Related Actors

Related Reports

« Back