Distribution of Backdoor via Malicious LNK: RedEyes (ScarCruft)
2023-09-06 • Ahnlab •
This malware executes additional scripts located at a specific URL through the mshta process. This command performs functions similar to those previously disclosed in Table 1 of the post <RedEyes Group Wiretapping Individuals (APT37)> [3]. The threat actor has been distributing the confirmed LNK file on a regular website by uploading it alongside malware within a compressed file. The malicious LNK file has been uploaded under the file name ‘REPORT.ZIP.’ Similar to the malware identified in <RokRAT Malware Distributed Through LNK Files (*.lnk): RedEyes (ScarCruft)> [2], this file has an LNK that contains normal Excel document data and malicious script code.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 27f74072d6268b5d96d73107c560d852 | 2023-09-01 | 2023-09-06 |
| HASH | 0eb8db3cbde470407f942fd63afe42b8 | 2023-08-22 | 2023-09-06 |
| HASH | 2d444b6f72c8327d1d155faa2cca7fd7 | 2023-08-22 | 2023-09-06 |
| URL | http://bian0151.cafe24.com/admi… | 2023-08-22 | 2023-09-06 |
| DOMAIN | bian0151.cafe24.com | 2023-08-22 | 2023-09-06 |
| IPv4 | 75.119.136.207 | 2023-07-11 | 2023-09-06 |