악성 LNK 분석: Malicious LNK analysis
2025-02-26 • Ssol2 • Cyber threat report on Kimsuky, LNK •
A malicious LNK sample shared on X with a Kimsuky tag used a DOCX icon lure and embedded an mshta.exe command, though the author cautions against relying heavily on the group label. LECmd analysis showed the shortcut extracting data from offset 0x0938 into c:\programdata\n.ps1 and launching it with PowerShell execution-policy bypass. The dropped PowerShell script used reversed string indexing and base64-encoded content before attempting to download payloads from Dropbox and a C2 server into c:\programdata\gs.zip, c:\programdata\k.zip, and c:\programdata\tmps2.ps1. The unavailable remote payloads limited final-stage analysis, but decoded behavior indicated persistence through Run registry modification and scheduled task creation, with useful artifacts including SHA256 hashes, file paths, Machine ID, MAC address, and SID values from the LNK.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 64.20.59.148 | 2025-02-26 | 2025-05-13 |
| HASH | 563a1cfd8788542cc19db91a52b8754… | 2025-02-26 | 2025-02-26 |
| HASH | 0a40d68cf5342a9b9fdc5fbc2900d6ed | 2025-02-26 | 2025-02-26 |
| HASH | b54fdd6e637315cb0a24a9b1ae5563c… | 2025-02-26 | 2025-02-26 |