Backdoor를 유포하는 악성 LNK : RedEyes(ScarCruft)

2023-09-01 • Ahnlab • Malicious LNK spreading Backdoor: RedEyes (ScarCruft) •

https://asec.ahnlab.com/ko/56526/

Thumbnail for Backdoor를 유포하는 악성 LNK : RedEyes(ScarCruft)

AhnLab analyzed RedEyes/ScarCruft malware distributed as malicious LNK files, including a REPORT.ZIP archive hosted on a legitimate site and disguised with a decoy Korean public-agency Excel document. When executed, the LNK used PowerShell to extract the decoy XLSX and a BAT script, copied the script into the user profile, and registered RunOnce persistence under HKCU. The decoded PowerShell chain invoked mshta to retrieve additional script code and communicated with 75.119.136[.]207 and bian0151.cafe24[.]com for command retrieval and result reporting. Supported commands included clipboard and process collection, file listing, command execution, plugin download, file download, and upload, showing an actively maintained backdoor capability.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 562a4d8980acda8411fc1f830cb9bb5… 2023-09-01 2023-09-06
HASH a39831ecbe0792adf87f63fb9955735… 2023-08-22 2023-09-06
HASH ebd20c8c63690965267c97348f4db89… 2023-08-22 2023-09-06
URL http://bian0151.cafe24.com/admi… 2023-08-22 2023-09-06
DOMAIN bian0151.cafe24.com 2023-08-22 2023-09-06
IPv4 75.119.136.207 2023-08-22 2023-09-06

Related Actors

Related Reports

« Back