Backdoor를 유포하는 악성 LNK : RedEyes(ScarCruft)

2023-09-01 Ahnlab Malicious LNK spreading Backdoor: RedEyes (ScarCruft)

https://asec.ahnlab.com/ko/56526/

Thumbnail for Backdoor를 유포하는 악성 LNK : RedEyes(ScarCruft)

AhnLab analyzed RedEyes/ScarCruft malware distributed as malicious LNK files, including a REPORT.ZIP archive hosted on a legitimate site and disguised with a decoy Korean public-agency Excel document. When executed, the LNK used PowerShell to extract the decoy XLSX and a BAT script, copied the script into the user profile, and registered RunOnce persistence under HKCU. The decoded PowerShell chain invoked mshta to retrieve additional script code and communicated with 75.119.136[.]207 and bian0151.cafe24[.]com for command retrieval and result reporting. Supported commands included clipboard and process collection, file listing, command execution, plugin download, file download, and upload, showing an actively maintained backdoor capability.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 27f74072d6268b5d96d73107c560d852 2023-09-01 2023-09-06
HASH 0eb8db3cbde470407f942fd63afe42b8 2023-08-22 2023-09-06
HASH 2d444b6f72c8327d1d155faa2cca7fd7 2023-08-22 2023-09-06
URL http://bian0151.cafe24.com/admi… 2023-08-22 2023-09-06
DOMAIN bian0151.cafe24.com 2023-08-22 2023-09-06
IPv4 75.119.136.207 2023-07-11 2023-09-06

Related Actors

Related Reports

« Back