Kimsuky APT组织利用blogspot分发恶意载荷的攻击活动分析

2021-07-19 • Qianxin • Analysis of attack activities of Kimsuky APT organization using blogspot to distribute malicious payloads •

https://ti.qianxin.com/blog/articles/Analysis-of-attack-activities-of-Kimsuky-APT-group-using-blogspot-to-distribute-malicious-payloads/

Thumbnail for Kimsuky APT组织利用blogspot分发恶意载荷的攻击活动分析

QiAnXin attributed several captured malicious document samples to Kimsuky, describing Korean fee-payment lures that displayed decoy content while inducing victims to enable malicious VBA. The core macro monitored text input before downloading Base64-encoded data from 1213rt.atwebpages.com, writing a VBS script as %AppData%\Microsoft\desktop.ini, and creating a startup shortcut named Internet Explorer.lnk for persistence. The VBS then retrieved an embedded payload from a Blogspot page such as kimshan600000.blogspot.com/2021/07/1.html, adding layers to the download chain and complicating attribution. The reported final backdoor behavior focused on system reconnaissance, including Microsoft Office Excel version collection and exfiltration to attacker infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 811b42bb169f02d1b0b3527e2ca6c00… 2021-06-09 2021-11-10
HASH e7fae41c0bd8d3d95253bd75dce9901… 2021-07-19 2021-09-01
DOMAIN wbg0909.scienceontheweb.net 2021-07-19 2021-09-01
URL http://alyssalove.getenjoyment.… 2021-06-09 2021-09-01
DOMAIN alyssalove.getenjoyment.net 2021-06-09 2021-09-01
HASH d3138e7b0dcf5e916834b045c1b006a… 2021-07-19 2021-07-19
URL http://1213rt.atwebpages.com/co… 2021-07-19 2021-07-19
URL http://wbg0909.scienceontheweb.… 2021-07-19 2021-07-19
DOMAIN 1213rt.atwebpages.com 2021-07-19 2021-07-19

Related Actors

Related Reports

« Back