김수키(Kimsuky) 에서 만든 파워셀 악성코드-1.ps1(<-가칭 2025.3.13)

2025-03-17 Sakai PowerShell Malware Created by Kimsuky - 1.ps1 (tentative name, 2025.3.13)

https://wezard4u.tistory.com/429432

Thumbnail for 김수키(Kimsuky) 에서 만든 파워셀 악성코드-1.ps1(<-가칭 2025.3.13)

Kimsuky activity described in the source uses a PowerShell malware sample tracked as 1.ps1 to collect host, user, process, disk, and IP information into temporary files and stage the data for exfiltration. The report publishes hashes for the sample and shows a constructed command-and-control upload path impersonating Kakao account-related content, supporting detection of PowerShell-based reconnaissance and data theft tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6ffb5106d912e582bde2c095365fa37… 2025-03-17 2025-06-19
IPv4 101.36.114.190 2025-03-17 2025-06-19

Related Actors

Related Reports

« Back