공공기관을 사칭하여 유포 중인 악성코드 주의(LNK)

2023-11-09 Ahnlab Beware of malware being distributed pretending to be a public institution (LNK)

https://asec.ahnlab.com/ko/58818/

Thumbnail for 공공기관을 사칭하여 유포 중인 악성코드 주의(LNK)

ASEC reports a campaign distributing malicious LNK files through emails that impersonate secure mail and public institutions, mainly aimed at people working on unification and security issues. The lure archives contain normal HWP documents about Ministry of Unification brown-bag lunch or policy meeting themes alongside LNK files that drop obfuscated VBS scripts and open decoy documents. The malware reaches external URLs to download more scripts or TutRAT, which can run filelessly, set an attacker server, and support keylogging, browser credential theft, screenshots, and command execution. ASEC notes behavioral and C2-format similarities to earlier activity and lists C2 infrastructure including 165.154.230[.]24:8020 and several defanged download URLs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 64dee04b6e6404c14d10971adf35c3a7 2023-11-09 2024-04-17
HASH eb614c99614c3365bdc926a73ef7a492 2023-11-09 2024-04-17
HASH fb5aec165279015f17b29f9f2c730976 2023-11-09 2024-04-17
HASH b70bc31b537caf411f97a991d8292c5a 2023-11-09 2024-04-17
IPv4 165.154.230.24 2023-11-09 2024-04-17
HASH de7cd0de5372e7801dab5aafd9c19148 2023-11-09 2023-11-14
HASH 5e5a87d0034e80e6b86a64387779dc2e 2023-11-09 2023-11-14
HASH 209ac4185dfc1e4d72c035ecb7f98eac 2023-11-09 2023-11-14
HASH 0040aa9762c2534ac44d9a6ae7024d15 2023-11-09 2023-11-14
HASH d00aa4b1a3cd9373d49c023580711170 2023-11-09 2023-11-14
HASH 40b7c3bced2975d70359a07c4f110f18 2023-11-09 2023-11-14

Related Actors

Related Reports

« Back