국내 금융 기업 대상으로 유포 중인 악성 LNK

2024-07-25 Ahnlab Malicious LNK Being Distributed to Domestic Financial Companies

https://asec.ahnlab.com/ko/68266/

Thumbnail for 국내 금융 기업 대상으로 유포 중인 악성 LNK

ASEC reports malicious LNK files being distributed against domestic financial companies through emails containing a URL that downloads a ZIP named as a financial-authority project information request. The archive contains a decoy PDF about virtual-currency project updates and a large LNK made to resemble an Excel file, which runs heavily obfuscated PowerShell. The LNK extracts a normal spreadsheet and a malicious CAB file, opens the decoy content, expands the CAB, executes start.vbs, registers persistence through a Run key, and runs batch scripts for information theft and additional downloads. Stolen user information is sent to hxxp://shutss[.]com/upload.php, while follow-on ZIP and CAB download paths include thevintagegarage[.]com and shutss[.]com endpoints. ASEC notes the overall file formats, commands, and URL patterns resemble earlier activity, while the script obfuscation has become more complex to hinder analysis and detection.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://thevintagegarage.com/pl… 2024-07-25 2025-05-19
DOMAIN thevintagegarage.com 2024-07-25 2025-05-19
HASH e3eeeebb117b7c3128d87b6e027bd85d 2024-07-25 2024-07-25
URL http://shutss.com/list.php?f=%C… 2024-07-25 2024-07-25
URL http://shutss.com/upload.php 2024-07-25 2024-07-25
URL https://cumasufitness.com/wp-in… 2024-07-25 2024-07-25
DOMAIN cumasufitness.com 2024-07-25 2024-07-25
DOMAIN shutss.com 2024-07-25 2024-07-25

Related Reports

« Back