Decryptor to celebrate Lunar New Year (Present From Kimsuky?!?!)

2020-01-23 • kino •

https://sfkino.tistory.com/77

The Korean malware analysis links a Lunar New Year-themed sample to activity resembling an earlier Vietnamese event estimate lure associated with Kimsuky reporting. The executable contains a PDF decoy instead of an HWP document, drops and runs a malicious DLL, and uses encrypted strings that the author decodes with an IDA script. The source highlights a backdoor communicating with happy-new-year.esy.es and publishes representative hashes for the dropper and related payloads. The report is useful for tracking repeated lure formats, DLL-dropping behavior, string encryption, and infrastructure reuse around Kimsuky-attributed activity without overextending the attribution beyond the author’s cautious framing.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6d870937675b98355747ecfdf4768b2… 2020-01-23 2020-06-25
HASH e2487b33a6510d6f51b8aa158a36c6c… 2020-01-23 2020-02-06
HASH f7e04d06690cc6c2fa699c70b9f95ac… 2020-01-23 2020-01-23

Related Actors

Related Reports

« Back