Backdoor를 유포하는 악성 LNK : RedEyes(ScarCruft)
2023-09-01 • Ahnlab • Malicious LNK spreading Backdoor: RedEyes (ScarCruft) •
AhnLab analyzed RedEyes/ScarCruft malware distributed as malicious LNK files, including a REPORT.ZIP archive hosted on a legitimate site and disguised with a decoy Korean public-agency Excel document. When executed, the LNK used PowerShell to extract the decoy XLSX and a BAT script, copied the script into the user profile, and registered RunOnce persistence under HKCU. The decoded PowerShell chain invoked mshta to retrieve additional script code and communicated with 75.119.136[.]207 and bian0151.cafe24[.]com for command retrieval and result reporting. Supported commands included clipboard and process collection, file listing, command execution, plugin download, file download, and upload, showing an actively maintained backdoor capability.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 27f74072d6268b5d96d73107c560d852 | 2023-09-01 | 2023-09-06 |
| HASH | 0eb8db3cbde470407f942fd63afe42b8 | 2023-08-22 | 2023-09-06 |
| HASH | 2d444b6f72c8327d1d155faa2cca7fd7 | 2023-08-22 | 2023-09-06 |
| URL | http://bian0151.cafe24.com/admi… | 2023-08-22 | 2023-09-06 |
| DOMAIN | bian0151.cafe24.com | 2023-08-22 | 2023-09-06 |
| IPv4 | 75.119.136.207 | 2023-07-11 | 2023-09-06 |