Kimsuky "AutoUpdate" Malware

2020-06-19 • Threatconnect •

http://web.archive.org/web/20210412184406/https://threatconnect.com/blog/threatconnect-research-roundup-kimsuky-autoupdate-malware/

Thumbnail for Kimsuky "AutoUpdate" Malware

ThreatConnect highlighted a suspected Kimsuky AutoUpdate malware sample connected to behavior described in ESTsecurity’s Operation Blue Estimate reporting. The source says the earlier file C315DE8AC15B51163A3BC075063A58AA was identified as a downloader, and ThreatConnect used its string deobfuscation routine and URL parameters to identify an additional related sample, FF0DDDC847825F13001B08661B2C7D0D. A hard-coded command-and-control domain was also noted in the incident, although the excerpt does not preserve the domain value. The report helps defenders correlate Kimsuky-linked downloader variants through shared deobfuscation logic, URL-parameter patterns, and embedded C2 configuration.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6d870937675b98355747ecfdf4768b2… 2020-01-23 2020-06-25
HASH 16c621580603afa3e1286642ea2df01… 2020-06-19 2020-06-19
URL https://cofense.com/zoom-phish-… 2020-06-19 2020-06-19
URL https://paste.cryptolaemus.com/… 2020-06-19 2020-06-19

Related Actors

Related Reports

« Back