공공기관을 사칭하여 유포 중인 악성코드 주의(LNK)
2023-11-09 • Ahnlab • Beware of malware being distributed pretending to be a public institution (LNK) •
ASEC reports a campaign distributing malicious LNK files through emails that impersonate secure mail and public institutions, mainly aimed at people working on unification and security issues. The lure archives contain normal HWP documents about Ministry of Unification brown-bag lunch or policy meeting themes alongside LNK files that drop obfuscated VBS scripts and open decoy documents. The malware reaches external URLs to download more scripts or TutRAT, which can run filelessly, set an attacker server, and support keylogging, browser credential theft, screenshots, and command execution. ASEC notes behavioral and C2-format similarities to earlier activity and lists C2 infrastructure including 165.154.230[.]24:8020 and several defanged download URLs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 64dee04b6e6404c14d10971adf35c3a7 | 2023-11-09 | 2024-04-17 |
| HASH | eb614c99614c3365bdc926a73ef7a492 | 2023-11-09 | 2024-04-17 |
| HASH | fb5aec165279015f17b29f9f2c730976 | 2023-11-09 | 2024-04-17 |
| HASH | b70bc31b537caf411f97a991d8292c5a | 2023-11-09 | 2024-04-17 |
| IPv4 | 165.154.230.24 | 2023-11-09 | 2024-04-17 |
| HASH | de7cd0de5372e7801dab5aafd9c19148 | 2023-11-09 | 2023-11-14 |
| HASH | 5e5a87d0034e80e6b86a64387779dc2e | 2023-11-09 | 2023-11-14 |
| HASH | 209ac4185dfc1e4d72c035ecb7f98eac | 2023-11-09 | 2023-11-14 |
| HASH | 0040aa9762c2534ac44d9a6ae7024d15 | 2023-11-09 | 2023-11-14 |
| HASH | d00aa4b1a3cd9373d49c023580711170 | 2023-11-09 | 2023-11-14 |
| HASH | 40b7c3bced2975d70359a07c4f110f18 | 2023-11-09 | 2023-11-14 |