게임 링크 단축 및 수익 창출 LootLabs 으로 위장한것으로 추정 되는 김수키(Kimsuky) 악성코드-Twitch x Loot Lab Event-2025.msc(2024.9.9)

2024-09-13 Sakai Kimsuky malware suspected of impersonating LootLabs game link monetization

http://wezard4u.tistory.com/429277

Thumbnail for 게임 링크 단축 및 수익 창출 LootLabs 으로 위장한것으로 추정 되는 김수키(Kimsuky) 악성코드-Twitch x Loot Lab Event-2025.msc(2024.9.9)

A Kimsuky-attributed Windows MSC file is presented as a Twitch and LootLabs event lure and uses a Microsoft Word icon to make the console file appear legitimate. The embedded task launches PowerShell with a hidden window and downloads a remote script from oshi.at, which then reconstructs hex-encoded binary content. The script writes the payload as RfQK.mp3 in the Common Documents folder, renames it to RfQK.exe, and starts it through conhost.exe to reduce user visibility. The excerpt provides MD5, SHA-1, and SHA-256 hashes, making the sample useful for tracking Kimsuky lure themes, MSC abuse, and script-based payload staging.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4bf38af3605e439d2de62f353c5829c… 2024-09-13 2024-09-13
HASH 41c656c497d7ec24de57a9927c13e81c 2024-09-13 2024-09-13
HASH 5042f64c0c5b1325964279106f0afa3… 2024-09-13 2024-09-13
URL https://oshi.at/PTgX/jIML.txt 2024-09-13 2024-09-13
DOMAIN oshi.at 2024-09-13 2024-09-13

Related Actors

Related Reports

« Back