북 해킹조직, 대용량 악성LNK 파일을 이용한 공격 진행중!

2023-05-18 ESTSecurity North Korean hacking organization is conducting an attack using large malicious LNK files!

https://blog.alyac.co.kr/5147

Thumbnail for 북 해킹조직, 대용량 악성LNK 파일을 이용한 공격 진행중!

ESRC warned that a North Korea-sponsored hacking group was abusing oversized LNK files in Korean-themed attacks after earlier Fair Trade Commission impersonation activity. The lures used current political and social topics such as the Washington Declaration and irregular tax-audit notices, padded the LNK files with large dummy data, and displayed HWP decoys while launching PowerShell or batch scripts. Execution downloaded additional shellcode or ran information-stealing and downloader scripts, with ALYac detecting the files as Trojan.Agent.LNK.Gen and Trojan.PowerShell.Agent. The report lists MD5 samples and infrastructure including OneDrive API delivery and centhosting.net endpoints, making oversized shortcut files a key defensive hunting clue.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://centhosting.net/upload.p… 2023-05-05 2023-11-24
DOMAIN centhosting.net 2023-05-05 2023-11-24
HASH 02685c2ffc30c55667076cfb01033060 2023-05-18 2023-07-11
HASH 445e7fd6bb684420d6b8523fe0c55228 2023-05-18 2023-07-11
HASH 278184b974d5232934ebf3f9ca9be5c8 2023-05-18 2023-05-18
HASH 2e0b68286c2673b12406c98c4c13b739 2023-05-18 2023-05-18
URL http://centhosting.net/list.php 2023-05-18 2023-05-18
URL https://1drv.ms/i/s!AhXEXLJSNMP… 2023-05-18 2023-05-18
URL https://api.onedrive.com/v1.0/s… 2023-05-18 2023-05-18
HASH 58d726099fdd9fdb8c34e96e13473aa4 2023-05-05 2023-05-18
HASH 2b2310574eb43608eec2540782e08b35 2023-05-05 2023-05-18

Related Reports

« Back