Distribution of Backdoor via Malicious LNK: RedEyes (ScarCruft)

2023-09-06 Ahnlab

https://asec.ahnlab.com/en/56756/

Thumbnail for Distribution of Backdoor via Malicious LNK: RedEyes (ScarCruft)

This malware executes additional scripts located at a specific URL through the mshta process. This command performs functions similar to those previously disclosed in Table 1 of the post <RedEyes Group Wiretapping Individuals (APT37)> [3]. The threat actor has been distributing the confirmed LNK file on a regular website by uploading it alongside malware within a compressed file. The malicious LNK file has been uploaded under the file name ‘REPORT.ZIP.’ Similar to the malware identified in <RokRAT Malware Distributed Through LNK Files (*.lnk): RedEyes (ScarCruft)> [2], this file has an LNK that contains normal Excel document data and malicious script code.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 27f74072d6268b5d96d73107c560d852 2023-09-01 2023-09-06
HASH 0eb8db3cbde470407f942fd63afe42b8 2023-08-22 2023-09-06
HASH 2d444b6f72c8327d1d155faa2cca7fd7 2023-08-22 2023-09-06
URL http://bian0151.cafe24.com/admi… 2023-08-22 2023-09-06
DOMAIN bian0151.cafe24.com 2023-08-22 2023-09-06
IPv4 75.119.136.207 2023-07-11 2023-09-06

Related Actors

Related Reports

« Back