북 해킹조직, 대용량 악성LNK 파일을 이용한 공격 진행중!
2023-05-18 • ESTSecurity • North Korean hacking organization is conducting an attack using large malicious LNK files! •
ESRC warned that a North Korea-sponsored hacking group was abusing oversized LNK files in Korean-themed attacks after earlier Fair Trade Commission impersonation activity. The lures used current political and social topics such as the Washington Declaration and irregular tax-audit notices, padded the LNK files with large dummy data, and displayed HWP decoys while launching PowerShell or batch scripts. Execution downloaded additional shellcode or ran information-stealing and downloader scripts, with ALYac detecting the files as Trojan.Agent.LNK.Gen and Trojan.PowerShell.Agent. The report lists MD5 samples and infrastructure including OneDrive API delivery and centhosting.net endpoints, making oversized shortcut files a key defensive hunting clue.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://centhosting.net/upload.p… | 2023-05-05 | 2023-11-24 |
| DOMAIN | centhosting.net | 2023-05-05 | 2023-11-24 |
| HASH | 02685c2ffc30c55667076cfb01033060 | 2023-05-18 | 2023-07-11 |
| HASH | 445e7fd6bb684420d6b8523fe0c55228 | 2023-05-18 | 2023-07-11 |
| HASH | 278184b974d5232934ebf3f9ca9be5c8 | 2023-05-18 | 2023-05-18 |
| HASH | 2e0b68286c2673b12406c98c4c13b739 | 2023-05-18 | 2023-05-18 |
| URL | http://centhosting.net/list.php | 2023-05-18 | 2023-05-18 |
| URL | https://1drv.ms/i/s!AhXEXLJSNMP… | 2023-05-18 | 2023-05-18 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-05-18 | 2023-05-18 |
| HASH | 58d726099fdd9fdb8c34e96e13473aa4 | 2023-05-05 | 2023-05-18 |
| HASH | 2b2310574eb43608eec2540782e08b35 | 2023-05-05 | 2023-05-18 |