Kimsuky 3

2024-03-12 • somedieyoung ZZ •

https://somedieyoungzz.github.io/posts/kimsuky-3/

The source analyzes a Kimsuky sample named like a Korean software security checklist for developers, using a double extension to make a VBScript look like an Excel macro file. The VBScript creates shell and file-system objects, writes large Base64 payloads under ProgramData or the Windows root, decodes one payload with certutil, launches the resulting decoy file, and runs a batch command that XOR-decodes another payload. It then executes the decoded component through regsvr32 and deletes the original script, making the lure useful for detecting developer-themed phishing, script obfuscation, Base64 staging, and living-off-the-land execution.

Indicators of Compromise

Type Value First Seen Last Seen
YARA kimsuky_VBS_script 2024-03-12 2024-03-12
DOMAIN tes.co 2024-03-12 2024-03-12
HASH db18e23bebb8581ba5670201cea98cc… 2022-09-14 2024-03-12
URL http://qwert.mine.bz/index.php 2022-09-14 2024-03-12
DOMAIN qwert.mine.bz 2022-09-14 2024-03-12
IPv4 216.189.154.6 2022-08-25 2024-03-12

Related Actors

Related Reports

« Back