정상 문서로 위장한 악성코드(kimsuky)

2023-02-03 • Ahnlab • Malware disguised as a normal document used by Kimsuky •

https://asec.ahnlab.com/ko/47147/

Thumbnail for 정상 문서로 위장한 악성코드(kimsuky)

AhnLab reports that Kimsuky-linked malicious documents previously seen against security-sector personnel were also being distributed to broadcasting and general enterprise users. The lure documents, including files resembling KBS interview questions and an app-planning document, used template injection to download malicious Word macro templates from compromised Korean web infrastructure. When macros executed, a batch file used curl to fetch a decoy document and a VBS payload, then exfiltrated antivirus, download-folder, and host information while registering scheduled-task persistence. Representative infrastructure included gdtech[.]kr, ddim.co[.]kr, hydrotec.co[.]kr, and jooshineng[.]com paths, with AhnLab detections for DOC.External and DOC.Kimsuky downloaders.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a2e6e833947a1d5c526c0c2d6943e35… 2023-02-03 2023-10-30
DOMAIN jooshineng.com 2023-02-03 2023-10-30
HASH ee3bd0aeb1d27bea0958399f64b9074… 2023-02-03 2023-02-15
HASH 486b279a9988871c329e2bbe14328f3… 2023-02-03 2023-02-15
HASH 873b2b0656ee9f6912390b5abc32b276 2023-02-03 2023-02-15
URL http://jooshineng.com/gnuboard4… 2023-02-03 2023-02-15
URL http://www.hydrotec.co.kr/bbs/i… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
URL http://www.hydrotec.co.kr/bbs/i… 2023-02-03 2023-02-15
URL http://ddim.co.kr/gnuboard4/adm… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
URL http://ddim.co.kr/gnuboard4/adm… 2023-02-03 2023-02-15
URL http://www.hydrotec.co.kr/bbs/i… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
URL http://gdtech.kr/gnuboard4/adm/… 2023-02-03 2023-02-15
DOMAIN ddim.co.kr 2023-02-03 2023-02-15
DOMAIN gdtech.kr 2023-02-03 2023-02-15
HASH 3cdf9f829ed03e1ac17b72b636d84d0b 2023-02-03 2023-02-03

Related Actors

Related Reports

« Back