Kimsuky "AutoUpdate" Malware
2020-06-19 • Threatconnect •
ThreatConnect highlighted a suspected Kimsuky AutoUpdate malware sample connected to behavior described in ESTsecurity’s Operation Blue Estimate reporting. The source says the earlier file C315DE8AC15B51163A3BC075063A58AA was identified as a downloader, and ThreatConnect used its string deobfuscation routine and URL parameters to identify an additional related sample, FF0DDDC847825F13001B08661B2C7D0D. A hard-coded command-and-control domain was also noted in the incident, although the excerpt does not preserve the domain value. The report helps defenders correlate Kimsuky-linked downloader variants through shared deobfuscation logic, URL-parameter patterns, and embedded C2 configuration.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c315de8ac15b51163a3bc075063a58aa | 2020-01-23 | 2020-06-25 |
| HASH | ff0dddc847825f13001b08661b2c7d0d | 2020-06-19 | 2020-06-19 |
| URL | https://cofense.com/zoom-phish-… | 2020-06-19 | 2020-06-19 |
| URL | https://paste.cryptolaemus.com/… | 2020-06-19 | 2020-06-19 |