Decryptor to celebrate Lunar New Year (Present From Kimsuky?!?!)
2020-01-23 • kino •
The Korean malware analysis links a Lunar New Year-themed sample to activity resembling an earlier Vietnamese event estimate lure associated with Kimsuky reporting. The executable contains a PDF decoy instead of an HWP document, drops and runs a malicious DLL, and uses encrypted strings that the author decodes with an IDA script. The source highlights a backdoor communicating with happy-new-year.esy.es and publishes representative hashes for the dropper and related payloads. The report is useful for tracking repeated lure formats, DLL-dropping behavior, string encryption, and infrastructure reuse around Kimsuky-attributed activity without overextending the attribution beyond the author’s cautious framing.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6d870937675b98355747ecfdf4768b2… | 2020-01-23 | 2020-06-25 |
| HASH | e2487b33a6510d6f51b8aa158a36c6c… | 2020-01-23 | 2020-02-06 |
| HASH | f7e04d06690cc6c2fa699c70b9f95ac… | 2020-01-23 | 2020-01-23 |