김수키(Kimsuky)만든 링크 방식 악성코드-scarcurft.lnk(2023-04-19)

2023-07-04 • Sakai • Link-based malware created by Kimsuky - scarcurft.lnk (2023-04-19) •

https://wezard4u.tistory.com/6489

Thumbnail for 김수키(Kimsuky)만든 링크 방식 악성코드-scarcurft.lnk(2023-04-19)

The source analyzes a Kimsuky-attributed malicious Windows shortcut file named scarcurft.lnk that uses hidden PowerShell execution instead of Office macros. The LNK searches for a matching shortcut, extracts an embedded Korean-language PDF lure and a BAT payload into the temporary directory, opens the PDF as decoy content, and then runs the BAT file. The embedded PowerShell includes API calls such as GlobalAlloc, VirtualProtect, CreateThread, and WaitForSingleObject, downloads additional data from a OneDrive API URL, and writes decoded bytes into executable memory before launching them. The report highlights representative hashes for the LNK and frames the technique as a shift toward link-file delivery to bypass macro-focused defenses.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1e0b5d6b85fca648061fdaf2830c5a9… 2023-05-01 2023-07-04
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-07-04
URL https://1drv.ms/i/s!AhXEXLJSNMP… 2023-04-21 2023-07-04

Related Actors

Related Reports

« Back