LNK or Swim: Analysis & Simulation of Recent LNK Phishing
2024-06-17 • Splunk •
https://www.splunk.com/en_us/blog/security/lnk-phishing-analysis-simulation.html
Malicious Windows LNK shortcut files are shown as a recurring initial trigger in phishing chains because Windows hides the extension and attackers can disguise shortcuts as invoices, PDFs, or benign applications. The excerpt gives examples involving AsyncRAT, Rhadamanthys, and Ducktail, where LNK execution runs batch or PowerShell commands that download additional payloads from attacker-controlled C2 infrastructure. Several samples use Base64, caret-character command splitting, XOR-decrypted embedded content, CAB extraction, and the forfiles Windows utility to hinder analysis or proxy execution through legitimate tools. The more complex chain adds Run key persistence, launches VBS and batch components, collects system and user-folder information, and sends reconnaissance data to C2, giving defenders concrete behaviors to hunt around LNK-launched scripting, LOLBIN use, and staged downloads.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5fb0518c2ced3e2556da039dae3cfe8… | 2024-06-17 | 2024-06-17 |
| HASH | e86017b846165690bcaf38242e09df9… | 2024-06-17 | 2024-06-17 |
| HASH | 2e7aa640b2da6d9350afba1b8ad0b65… | 2024-06-17 | 2024-06-17 |
| HASH | 375ac09d5f44849e9c888e86adc5006… | 2024-06-17 | 2024-06-17 |
| HASH | 9566099319b9649f49501121f789e7e… | 2024-06-17 | 2024-06-17 |
| HASH | 4613810c0daf6abb2449de0816ef6c8… | 2024-06-17 | 2024-06-17 |
| URL | http://stuckss.com/list.php?f=%… | 2024-06-17 | 2024-06-17 |
| HASH | 27cd090cf83877750416d37dc6ddd8f… | 2024-03-11 | 2024-06-17 |
| URL | https://goosess.com/read/get.php | 2024-03-11 | 2024-06-17 |
| DOMAIN | stuckss.com | 2024-03-11 | 2024-06-17 |
| DOMAIN | goosess.com | 2024-03-11 | 2024-06-17 |