LNK or Swim: Analysis & Simulation of Recent LNK Phishing

2024-06-17 Splunk

https://www.splunk.com/en_us/blog/security/lnk-phishing-analysis-simulation.html

Thumbnail for LNK or Swim: Analysis & Simulation of Recent LNK Phishing

Malicious Windows LNK shortcut files are shown as a recurring initial trigger in phishing chains because Windows hides the extension and attackers can disguise shortcuts as invoices, PDFs, or benign applications. The excerpt gives examples involving AsyncRAT, Rhadamanthys, and Ducktail, where LNK execution runs batch or PowerShell commands that download additional payloads from attacker-controlled C2 infrastructure. Several samples use Base64, caret-character command splitting, XOR-decrypted embedded content, CAB extraction, and the forfiles Windows utility to hinder analysis or proxy execution through legitimate tools. The more complex chain adds Run key persistence, launches VBS and batch components, collects system and user-folder information, and sends reconnaissance data to C2, giving defenders concrete behaviors to hunt around LNK-launched scripting, LOLBIN use, and staged downloads.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5fb0518c2ced3e2556da039dae3cfe8… 2024-06-17 2024-06-17
HASH e86017b846165690bcaf38242e09df9… 2024-06-17 2024-06-17
HASH 2e7aa640b2da6d9350afba1b8ad0b65… 2024-06-17 2024-06-17
HASH 375ac09d5f44849e9c888e86adc5006… 2024-06-17 2024-06-17
HASH 9566099319b9649f49501121f789e7e… 2024-06-17 2024-06-17
HASH 4613810c0daf6abb2449de0816ef6c8… 2024-06-17 2024-06-17
URL http://stuckss.com/list.php?f=%… 2024-06-17 2024-06-17
HASH 27cd090cf83877750416d37dc6ddd8f… 2024-03-11 2024-06-17
URL https://goosess.com/read/get.php 2024-03-11 2024-06-17
DOMAIN stuckss.com 2024-03-11 2024-06-17
DOMAIN goosess.com 2024-03-11 2024-06-17

Related Reports

« Back