EDR 제품을 통한 RokRAT 유포 링크 파일(*.lnk) 추적 및 대응
2023-04-28 • Ahnlab • Track and respond to RokRAT distribution link files (*.lnk) through EDR products •
AhnLab reported follow-on EDR tracking for RedEyes, also known as APT37 or ScarCruft, after the group distributed CHM malware disguised as security mail from a domestic financial company. The source describes malicious LNK files that contain PowerShell commands, create script files alongside legitimate files under a temp path, and run a decoy PDF so the victim is less likely to notice infection. AhnLab says its EDR can expose the suspicious PowerShell and batch-file execution chain, identify the affected host and logged-in user, and recover additional malware download URLs. The report links the activity to RokRAT distribution and provides LNK and BAT hashes plus OneDrive API download URLs as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://api.onedrive.com/v1.0/s… | 2023-04-21 | 2023-07-04 |
| URL | https://1drv.ms/i/s!AhXEXLJSNMP… | 2023-04-21 | 2023-07-04 |
| URL | https://1drv.ms/u/s!Au2my1xh6t8… | 2023-04-21 | 2023-06-06 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-04-21 | 2023-06-06 |
| HASH | aa8ba9a029fa98b868be66b7d46e927b | 2023-04-21 | 2023-05-23 |
| HASH | 0f5eeb23d701a2b342fc15aa90d97ae0 | 2023-04-21 | 2023-05-23 |
| HASH | 657fd7317ccde5a0e0c182a626951a9f | 2023-04-21 | 2023-05-23 |
| HASH | be32725e676d49eaa11ff51c61f18907 | 2023-04-21 | 2023-05-23 |
| HASH | 461ce7d6c6062d1ae33895d1f44d98fb | 2023-04-21 | 2023-04-28 |
| HASH | 8fef5eb77e0a9ef2f97591d4d150a363 | 2023-04-21 | 2023-04-28 |