김수키(Kimsuky)만든 링크 방식 악성코드-scarcurft.lnk(2023-04-19)
2023-07-04 • Sakai • Link-based malware created by Kimsuky - scarcurft.lnk (2023-04-19) •
The source analyzes a Kimsuky-attributed malicious Windows shortcut file named scarcurft.lnk that uses hidden PowerShell execution instead of Office macros. The LNK searches for a matching shortcut, extracts an embedded Korean-language PDF lure and a BAT payload into the temporary directory, opens the PDF as decoy content, and then runs the BAT file. The embedded PowerShell includes API calls such as GlobalAlloc, VirtualProtect, CreateThread, and WaitForSingleObject, downloads additional data from a OneDrive API URL, and writes decoded bytes into executable memory before launching them. The report highlights representative hashes for the LNK and frames the technique as a shift toward link-file delivery to bypass macro-focused defenses.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d38ed1f834c168e5b8759d534d047e0… | 2023-07-04 | 2023-07-04 |
| HASH | e233e4da734f75388b40fed1717bfb6a | 2023-05-23 | 2023-07-04 |
| HASH | 1e0b5d6b85fca648061fdaf2830c5a9… | 2023-05-01 | 2023-07-04 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-04-21 | 2023-07-04 |
| URL | https://1drv.ms/i/s!AhXEXLJSNMP… | 2023-04-21 | 2023-07-04 |