Kimsuky A Gift That Keeps on Giving

2024-09-17 somedieyoung ZZ

https://somedieyoungzz.github.io/posts/kimsuky-6/

Thumbnail for Kimsuky A Gift That Keeps on Giving

The analysis covers a Windows LNK sample whose TTPs are assessed by the author as consistent with Kimsuky or another DPRK-based actor. The shortcut uses mshta.exe and JavaScript arguments to reach 64.49.14.181, retrieve a Base64-encoded ZIP, write it as C:\ProgramData\t.zip, extract it, and run s.vbs. The VBScript uses obfuscation and a Caesar-style decoding routine, creates a scheduled task disguised as an Edge update, and opens a decoy DOCX from ProgramData. Later stages add Run-key persistence for a VBS file and execute PowerShell against C:\ProgramData\xM578.tmp, giving defenders concrete Windows persistence and staging behaviors to hunt.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 64.49.14.181 2024-09-17 2024-09-26
HASH c4aba442d881cfa112fe3a6b1d2381b… 2024-09-17 2024-09-20
HASH 41cf6298a41c27357ee5f70d8cd1c0b… 2024-09-17 2024-09-20
HASH b7fc11f37433b4f1d357e43b5a26802… 2024-09-17 2024-09-17
HASH 2da46ae5dbabc6442cc0d2698725dae… 2024-09-17 2024-09-17
HASH 40c9f86e343f5a54570162bcca2d18f… 2024-09-17 2024-09-17

Related Actors

Related Reports

« Back