주중대사관 을 타겟으로 추측이 되는 Kimsuky(김수키) 만든 악성코드-202404주중대사관 정책간담회.rar(2024.3.29)

2024-04-03 • Sakai • Malware Created by Kimsuky Suspected of Targeting the Chinese Embassy - 202404 Chinese Embassy Policy Meeting.rar (2024.3.29) •

http://wezard4u.tistory.com/6776

Thumbnail for 주중대사관 을 타겟으로 추측이 되는 Kimsuky(김수키) 만든 악성코드-202404주중대사관 정책간담회.rar(2024.3.29)

A Kimsuky-attributed RAR archive used a Korean Embassy in China policy-meeting theme to lure likely embassy or policy-related personnel into running a shortcut file disguised with an HWP-style document icon. The LNK launches hidden PowerShell, extracts embedded content, deletes the original shortcut, contacts Dropbox via API credentials, downloads /step5/ps.bin, AES-decrypts it with a hardcoded password, and executes the resulting script. The lure document impersonates a private Korea-China and North Korea-China security policy meeting plan, supporting the social-engineering angle against diplomatic or government-linked targets. The excerpt provides file hashes for the RAR, LNK, and generated artifact, a Google Drive delivery URL, a Dropbox download path, and antivirus detections including LNK/Kimsuky and Powecod-style behavior.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fe156159a26f8b7c140db61dd8b136e… 2024-04-03 2024-04-17
HASH 32e739ea04e2afc0f73d54f78f08cc3… 2024-04-03 2024-04-03
HASH e9a73243f0fbd158ad0113753c3b289… 2024-04-03 2024-04-03
EMAIL [email protected] 2024-04-03 2024-04-03
URL https://content.dropboxapi.com/… 2024-04-03 2024-04-03
DOMAIN system.io.me 2024-04-03 2024-04-03
URL https://api.dropboxapi.com/oaut… 2024-03-28 2024-04-03

Related Actors

Related Reports

« Back