EDR 제품을 통한 RokRAT 유포 링크 파일(*.lnk) 추적 및 대응
2023-04-28 • Ahnlab • Track and respond to RokRAT distribution link files (*.lnk) through EDR products •
AhnLab reported follow-on EDR tracking for RedEyes, also known as APT37 or ScarCruft, after the group distributed CHM malware disguised as security mail from a domestic financial company. The source describes malicious LNK files that contain PowerShell commands, create script files alongside legitimate files under a temp path, and run a decoy PDF so the victim is less likely to notice infection. AhnLab says its EDR can expose the suspicious PowerShell and batch-file execution chain, identify the affected host and logged-in user, and recover additional malware download URLs. The report links the activity to RokRAT distribution and provides LNK and BAT hashes plus OneDrive API download URLs as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://api.onedrive.com/v1.0/s… | 2023-04-21 | 2023-07-04 |
| URL | https://1drv.ms/i/s!AhXEXLJSNMP… | 2023-04-21 | 2023-07-04 |
| HASH | f92297c4efabba98befeb992a009462… | 2023-04-21 | 2023-06-06 |
| HASH | 06431a5d8f6262cc3db39d911a920f7… | 2023-04-21 | 2023-06-06 |
| URL | https://1drv.ms/u/s!Au2my1xh6t8… | 2023-04-21 | 2023-06-06 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-04-21 | 2023-06-06 |
| HASH | 0f5eeb23d701a2b342fc15aa90d97ae0 | 2023-04-21 | 2023-05-23 |
| HASH | c5c05f9df89fc803884fed2bd20a382… | 2023-04-21 | 2023-05-23 |
| HASH | 479894be4c5dec0992ad3c5b21fb142… | 2023-04-21 | 2023-05-23 |
| HASH | 70f9216f0c5badb24120f74270dbbc5… | 2023-04-21 | 2023-05-01 |