국내 금융 기업 대상으로 유포 중인 악성 LNK
2024-07-25 • Ahnlab • Malicious LNK Being Distributed to Domestic Financial Companies •
ASEC reports malicious LNK files being distributed against domestic financial companies through emails containing a URL that downloads a ZIP named as a financial-authority project information request. The archive contains a decoy PDF about virtual-currency project updates and a large LNK made to resemble an Excel file, which runs heavily obfuscated PowerShell. The LNK extracts a normal spreadsheet and a malicious CAB file, opens the decoy content, expands the CAB, executes start.vbs, registers persistence through a Run key, and runs batch scripts for information theft and additional downloads. Stolen user information is sent to hxxp://shutss[.]com/upload.php, while follow-on ZIP and CAB download paths include thevintagegarage[.]com and shutss[.]com endpoints. ASEC notes the overall file formats, commands, and URL patterns resemble earlier activity, while the script obfuscation has become more complex to hinder analysis and detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://thevintagegarage.com/pl… | 2024-07-25 | 2025-05-19 |
| DOMAIN | thevintagegarage.com | 2024-07-25 | 2025-05-19 |
| HASH | e3eeeebb117b7c3128d87b6e027bd85d | 2024-07-25 | 2024-07-25 |
| URL | http://shutss.com/list.php?f=%C… | 2024-07-25 | 2024-07-25 |
| URL | http://shutss.com/upload.php | 2024-07-25 | 2024-07-25 |
| URL | https://cumasufitness.com/wp-in… | 2024-07-25 | 2024-07-25 |
| DOMAIN | cumasufitness.com | 2024-07-25 | 2024-07-25 |
| DOMAIN | shutss.com | 2024-07-25 | 2024-07-25 |