게임 링크 단축 및 수익 창출 LootLabs 으로 위장한것으로 추정 되는 김수키(Kimsuky) 악성코드-Twitch x Loot Lab Event-2025.msc(2024.9.9)
2024-09-13 • Sakai • Kimsuky malware suspected of impersonating LootLabs game link monetization •
A Kimsuky-attributed Windows MSC file is presented as a Twitch and LootLabs event lure and uses a Microsoft Word icon to make the console file appear legitimate. The embedded task launches PowerShell with a hidden window and downloads a remote script from oshi.at, which then reconstructs hex-encoded binary content. The script writes the payload as RfQK.mp3 in the Common Documents folder, renames it to RfQK.exe, and starts it through conhost.exe to reduce user visibility. The excerpt provides MD5, SHA-1, and SHA-256 hashes, making the sample useful for tracking Kimsuky lure themes, MSC abuse, and script-based payload staging.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4bf38af3605e439d2de62f353c5829c… | 2024-09-13 | 2024-09-13 |
| HASH | 41c656c497d7ec24de57a9927c13e81c | 2024-09-13 | 2024-09-13 |
| HASH | 5042f64c0c5b1325964279106f0afa3… | 2024-09-13 | 2024-09-13 |
| URL | https://oshi.at/PTgX/jIML.txt | 2024-09-13 | 2024-09-13 |
| DOMAIN | oshi.at | 2024-09-13 | 2024-09-13 |