EDR 제품을 통한 RokRAT 유포 링크 파일(*.lnk) 추적 및 대응

2023-04-28 • Ahnlab • Track and respond to RokRAT distribution link files (*.lnk) through EDR products •

https://asec.ahnlab.com/ko/51868/

Thumbnail for EDR 제품을 통한 RokRAT 유포 링크 파일(*.lnk) 추적 및 대응

AhnLab reported follow-on EDR tracking for RedEyes, also known as APT37 or ScarCruft, after the group distributed CHM malware disguised as security mail from a domestic financial company. The source describes malicious LNK files that contain PowerShell commands, create script files alongside legitimate files under a temp path, and run a decoy PDF so the victim is less likely to notice infection. AhnLab says its EDR can expose the suspicious PowerShell and batch-file execution chain, identify the affected host and logged-in user, and recover additional malware download URLs. The report links the activity to RokRAT distribution and provides LNK and BAT hashes plus OneDrive API download URLs as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-07-04
URL https://1drv.ms/i/s!AhXEXLJSNMP… 2023-04-21 2023-07-04
HASH f92297c4efabba98befeb992a009462… 2023-04-21 2023-06-06
HASH 06431a5d8f6262cc3db39d911a920f7… 2023-04-21 2023-06-06
URL https://1drv.ms/u/s!Au2my1xh6t8… 2023-04-21 2023-06-06
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-06-06
HASH 0f5eeb23d701a2b342fc15aa90d97ae0 2023-04-21 2023-05-23
HASH c5c05f9df89fc803884fed2bd20a382… 2023-04-21 2023-05-23
HASH 479894be4c5dec0992ad3c5b21fb142… 2023-04-21 2023-05-23
HASH 70f9216f0c5badb24120f74270dbbc5… 2023-04-21 2023-05-01

Related Actors

Related Reports

« Back