게임 업계 대상 MoonPeak 감염 사례 분석
2026-07-21 • Hauri • Analysis of a MoonPeak Infection Targeting the Gaming Industry •
Attachments
A malicious LNK disguised as a game-character design file launches a multistage PowerShell infection chain that checks the analysis environment and collects system information. The malware generates aes.js at runtime to steal cookies for command-and-control activity, establishes scheduled-task persistence, and downloads additional payloads. A GZIP payload disguised as an RTF file ultimately loads MoonPeak, a XenoRAT-based malware variant, while asynchronous socket communications and a mutex shared with earlier MoonPeak samples reinforce the identification.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a430f2132ed78ff72663823171332bed | 2026-07-21 | 2026-07-21 |
| HASH | 8680e930bf18c78bcdb967ff7a8b0145 | 2026-07-21 | 2026-07-21 |
| HASH | d957f2f932f379fbe30d06158d804005 | 2026-07-21 | 2026-07-21 |
| IPv4 | 38.180.204.13 | 2026-07-21 | 2026-07-21 |
| IPv4 | 107.172.249.140 | 2026-07-21 | 2026-07-21 |
| DOMAIN | un3i.freepage.cc | 2026-07-21 | 2026-07-21 |
Related Reports
Shares tag: LNK • Same author: Hauri • Published within a month
2026-05-14 •
36% Match
#Phishing
#VelvetChollima
#XenoRAT
#MoonPeak
#T1567.002
#T1056.001
#T1555.003
#T1053.005
#T1105
Shares tags: XenoRAT, MoonPeak
Shares tag: LNK • Published within a month
Shares tag: LNK • Published within a month
Shares tag: LNK • Published within a month
Shares tag: LNK • Published within a month