김수키(Kimsuky)에서 만든 코발트 스트라이크(Cobalt Strike) 악성코드-test.zip(2025.1.11)

2025-01-16 Sakai Cobalt Strike Malware Created by Kimsuky - test.zip (2025.1.11)

https://wezard4u.tistory.com/429381

Thumbnail for 김수키(Kimsuky)에서 만든 코발트 스트라이크(Cobalt Strike) 악성코드-test.zip(2025.1.11)

A Kimsuky-linked test.zip sample is described as a Cobalt Strike-related malware package that uses a Windows shortcut file to disguise execution as a document. The LNK uses a WordPad icon and launches hidden PowerShell that searches for a same-directory shortcut of exactly 395,530 bytes, reads its embedded data, writes a temporary ZIP from offset 3,412, expands it, deletes the temporary archive, and runs svchost.exe. The dropped svchost.exe payload is reported at 367,019,008 bytes, with hashes provided, and the malware references hxxp://c-csigns(.)com:443/686c6c647a_B(.)gif. Vendor detections identify the file as LNK dropper or Kimsuky-related malware, supporting detection opportunities around document-themed LNK lures, embedded archive extraction, hidden PowerShell, and masqueraded svchost execution.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hvil-telegram.org 2025-01-15 2025-01-24
HASH 0950e65c47b3f45d0ab1e9171aa4fa1… 2025-01-16 2025-01-16
HASH 8d3dd8b5a883a2080525a11807b2a6e1 2025-01-16 2025-01-16
HASH ce13fdeb751805770de676f0b387623… 2025-01-16 2025-01-16
HASH c2faf67cab95cba996e6b705e9579ff… 2025-01-16 2025-01-16
HASH da3cbfad064e12c4334161a00335c01… 2025-01-16 2025-01-16
HASH 7207593087e9fc954d40c212c1d7d715 2025-01-16 2025-01-16
URL http://c-csigns.com:443/686c6c6… 2025-01-16 2025-01-16
DOMAIN c-csigns.com 2025-01-16 2025-01-16

Related Actors

Related Reports

« Back