김수키(Kimsuky)만든 링크 방식 악성코드-scarcurft.lnk(2023-04-19)

2023-07-04 Sakai Link-based malware created by Kimsuky - scarcurft.lnk (2023-04-19)

https://wezard4u.tistory.com/6489

Thumbnail for 김수키(Kimsuky)만든 링크 방식 악성코드-scarcurft.lnk(2023-04-19)

The source analyzes a Kimsuky-attributed malicious Windows shortcut file named scarcurft.lnk that uses hidden PowerShell execution instead of Office macros. The LNK searches for a matching shortcut, extracts an embedded Korean-language PDF lure and a BAT payload into the temporary directory, opens the PDF as decoy content, and then runs the BAT file. The embedded PowerShell includes API calls such as GlobalAlloc, VirtualProtect, CreateThread, and WaitForSingleObject, downloads additional data from a OneDrive API URL, and writes decoded bytes into executable memory before launching them. The report highlights representative hashes for the LNK and frames the technique as a shift toward link-file delivery to bypass macro-focused defenses.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d38ed1f834c168e5b8759d534d047e0… 2023-07-04 2023-07-04
HASH e233e4da734f75388b40fed1717bfb6a 2023-05-23 2023-07-04
HASH 1e0b5d6b85fca648061fdaf2830c5a9… 2023-05-01 2023-07-04
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-07-04
URL https://1drv.ms/i/s!AhXEXLJSNMP… 2023-04-21 2023-07-04

Related Actors

Related Reports

« Back