김수키(Kimsuky)에서 만든 코발트 스트라이크(Cobalt Strike) 악성코드-test.zip(2025.1.11)

2025-01-16 Sakai Cobalt Strike Malware Created by Kimsuky - test.zip (2025.1.11)

https://wezard4u.tistory.com/429381

Thumbnail for 김수키(Kimsuky)에서 만든 코발트 스트라이크(Cobalt Strike) 악성코드-test.zip(2025.1.11)

A Kimsuky-linked test.zip sample is described as a Cobalt Strike-related malware package that uses a Windows shortcut file to disguise execution as a document. The LNK uses a WordPad icon and launches hidden PowerShell that searches for a same-directory shortcut of exactly 395,530 bytes, reads its embedded data, writes a temporary ZIP from offset 3,412, expands it, deletes the temporary archive, and runs svchost.exe. The dropped svchost.exe payload is reported at 367,019,008 bytes, with hashes provided, and the malware references hxxp://c-csigns(.)com:443/686c6c647a_B(.)gif. Vendor detections identify the file as LNK dropper or Kimsuky-related malware, supporting detection opportunities around document-themed LNK lures, embedded archive extraction, hidden PowerShell, and masqueraded svchost execution.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hvil-telegram.org 2025-01-15 2025-01-24
HASH c2faf67cab95cba996e6b705e9579ff… 2025-01-16 2025-01-16
HASH ce13fdeb751805770de676f0b387623… 2025-01-16 2025-01-16
URL http://c-csigns.com:443/686c6c6… 2025-01-16 2025-01-16
DOMAIN c-csigns.com 2025-01-16 2025-01-16

Related Actors

Related Reports

« Back