EDR 제품을 통한 RokRAT 유포 링크 파일(*.lnk) 추적 및 대응

2023-04-28 Ahnlab Track and respond to RokRAT distribution link files (*.lnk) through EDR products

https://asec.ahnlab.com/ko/51868/

Thumbnail for EDR 제품을 통한 RokRAT 유포 링크 파일(*.lnk) 추적 및 대응

AhnLab reported follow-on EDR tracking for RedEyes, also known as APT37 or ScarCruft, after the group distributed CHM malware disguised as security mail from a domestic financial company. The source describes malicious LNK files that contain PowerShell commands, create script files alongside legitimate files under a temp path, and run a decoy PDF so the victim is less likely to notice infection. AhnLab says its EDR can expose the suspicious PowerShell and batch-file execution chain, identify the affected host and logged-in user, and recover additional malware download URLs. The report links the activity to RokRAT distribution and provides LNK and BAT hashes plus OneDrive API download URLs as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-07-04
URL https://1drv.ms/i/s!AhXEXLJSNMP… 2023-04-21 2023-07-04
URL https://1drv.ms/u/s!Au2my1xh6t8… 2023-04-21 2023-06-06
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-06-06
HASH aa8ba9a029fa98b868be66b7d46e927b 2023-04-21 2023-05-23
HASH 0f5eeb23d701a2b342fc15aa90d97ae0 2023-04-21 2023-05-23
HASH 657fd7317ccde5a0e0c182a626951a9f 2023-04-21 2023-05-23
HASH be32725e676d49eaa11ff51c61f18907 2023-04-21 2023-05-23
HASH 461ce7d6c6062d1ae33895d1f44d98fb 2023-04-21 2023-04-28
HASH 8fef5eb77e0a9ef2f97591d4d150a363 2023-04-21 2023-04-28

Related Actors

Related Reports

« Back