Distribution of Backdoor via Malicious LNK: RedEyes (ScarCruft)

2023-09-06 • Ahnlab •

https://asec.ahnlab.com/en/56756/

Thumbnail for Distribution of Backdoor via Malicious LNK: RedEyes (ScarCruft)

This malware executes additional scripts located at a specific URL through the mshta process. This command performs functions similar to those previously disclosed in Table 1 of the post <RedEyes Group Wiretapping Individuals (APT37)> [3]. The threat actor has been distributing the confirmed LNK file on a regular website by uploading it alongside malware within a compressed file. The malicious LNK file has been uploaded under the file name ‘REPORT.ZIP.’ Similar to the malware identified in <RokRAT Malware Distributed Through LNK Files (*.lnk): RedEyes (ScarCruft)> [2], this file has an LNK that contains normal Excel document data and malicious script code.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 562a4d8980acda8411fc1f830cb9bb5… 2023-09-01 2023-09-06
HASH a39831ecbe0792adf87f63fb9955735… 2023-08-22 2023-09-06
HASH ebd20c8c63690965267c97348f4db89… 2023-08-22 2023-09-06
URL http://bian0151.cafe24.com/admi… 2023-08-22 2023-09-06
DOMAIN bian0151.cafe24.com 2023-08-22 2023-09-06
IPv4 75.119.136.207 2023-08-22 2023-09-06

Related Actors

Related Reports

« Back