김수키(Kimsuky)에서 만든 코발트 스트라이크(Cobalt Strike) 악성코드-test.zip(2025.1.11)
2025-01-16 • Sakai • Cobalt Strike Malware Created by Kimsuky - test.zip (2025.1.11) •
A Kimsuky-linked test.zip sample is described as a Cobalt Strike-related malware package that uses a Windows shortcut file to disguise execution as a document. The LNK uses a WordPad icon and launches hidden PowerShell that searches for a same-directory shortcut of exactly 395,530 bytes, reads its embedded data, writes a temporary ZIP from offset 3,412, expands it, deletes the temporary archive, and runs svchost.exe. The dropped svchost.exe payload is reported at 367,019,008 bytes, with hashes provided, and the malware references hxxp://c-csigns(.)com:443/686c6c647a_B(.)gif. Vendor detections identify the file as LNK dropper or Kimsuky-related malware, supporting detection opportunities around document-themed LNK lures, embedded archive extraction, hidden PowerShell, and masqueraded svchost execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | hvil-telegram.org | 2025-01-15 | 2025-01-24 |
| HASH | 0950e65c47b3f45d0ab1e9171aa4fa1… | 2025-01-16 | 2025-01-16 |
| HASH | 8d3dd8b5a883a2080525a11807b2a6e1 | 2025-01-16 | 2025-01-16 |
| HASH | ce13fdeb751805770de676f0b387623… | 2025-01-16 | 2025-01-16 |
| HASH | c2faf67cab95cba996e6b705e9579ff… | 2025-01-16 | 2025-01-16 |
| HASH | da3cbfad064e12c4334161a00335c01… | 2025-01-16 | 2025-01-16 |
| HASH | 7207593087e9fc954d40c212c1d7d715 | 2025-01-16 | 2025-01-16 |
| URL | http://c-csigns.com:443/686c6c6… | 2025-01-16 | 2025-01-16 |
| DOMAIN | c-csigns.com | 2025-01-16 | 2025-01-16 |