악성 LNK 분석: Malicious LNK analysis

2025-02-26 Ssol2 Cyber threat report on Kimsuky, LNK

https://ssol2.kr/%EC%95%85%EC%84%B1-lnk-%EB%B6%84%EC%84%9D-2025-02-23-9607a1f3975454e8dfb544191df953ce-hijackloader-ryuk-469e64318f14

A malicious LNK sample shared on X with a Kimsuky tag used a DOCX icon lure and embedded an mshta.exe command, though the author cautions against relying heavily on the group label. LECmd analysis showed the shortcut extracting data from offset 0x0938 into c:\programdata\n.ps1 and launching it with PowerShell execution-policy bypass. The dropped PowerShell script used reversed string indexing and base64-encoded content before attempting to download payloads from Dropbox and a C2 server into c:\programdata\gs.zip, c:\programdata\k.zip, and c:\programdata\tmps2.ps1. The unavailable remote payloads limited final-stage analysis, but decoded behavior indicated persistence through Run registry modification and scheduled task creation, with useful artifacts including SHA256 hashes, file paths, Machine ID, MAC address, and SID values from the LNK.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 64.20.59.148 2025-02-26 2025-05-13
HASH 563a1cfd8788542cc19db91a52b8754… 2025-02-26 2025-02-26
HASH 0a40d68cf5342a9b9fdc5fbc2900d6ed 2025-02-26 2025-02-26
HASH b54fdd6e637315cb0a24a9b1ae5563c… 2025-02-26 2025-02-26

Related Actors

Related Reports

« Back