VBS Script Disguised as PDF File Being Distributed (Kimsuky) - ASEC BLOG
Common Information
Type Value
UUID 2c9eadfd-9f1e-489e-a2fb-1df2c0e5bb13
Fingerprint b49b9d9b49bf42a4
Analysis status DONE
Considered CTI value 2
Text language
Published March 28, 2022, 9:13 a.m.
Added to db Sept. 11, 2022, 4:59 p.m.
Last updated Nov. 18, 2024, 1:38 a.m.
Headline VBS Script Disguised as PDF File Being Distributed (Kimsuky)
Title VBS Script Disguised as PDF File Being Distributed (Kimsuky) - ASEC BLOG
Detected Hints/Tags/Attributes 32/2/11
Source URLs
Attributes
Details Type #Events CTI Value
Details Domain 7
kro.kr
Details Domain 2
regular.winupdate.kro.kr
Details File 5
pdf.vbs
Details File 459
regsvr32.exe
Details File 2127
cmd.exe
Details File 1206
index.php
Details md5 1
b3c7df17420d48f61bbfcf2bac3ae4a3
Details md5 1
64cbd6f435538175dc06ea4b84cba46d
Details md5 1
856072827cec7b74ead3ce40e55bd8d1
Details md5 1
3ea9b50289aecccc7ffd04fa814c1a5c
Details Url 1
https://regular.winupdate.kro.kr/index.php