🦠 Malware Analysis
===================
🦠 Malware Analysis
Executive summary: A recently observed campaign leverages malicious
Windows shortcut files (.LNK) distributed via Discord to deliver a
multi‑functional Remote Access Trojan (RAT). The LNK triggers a hidden
PowerShell that extracts a ZIP (Moq.zip) containing a malicious DLL
and executes it through the legitimate binary odbcconf.exe, a
Living‑off‑the‑Land Binary (LOLBin), to evade detection.
Technical details:
• The shortcut named Cyber security.lnk opens an embedded decoy PDF
Cyber security.pdf while running a PowerShell payload in hidden mode
(via a headless conhost.exe).
• The PowerShell creates a working path (Temp and a Nuget folder under
Public), extracts an embedded PDF and the ZIP archive, then drops
Moq.zip and a malicious DLL.
• Execution is handed to odbcconf.exe to load the DLL, enabling
process execution without spawning visible consoles.
• The RAT collects system/antivirus information, attempts AMSI
bypasses, and patches EtwEventWrite to impair Windows Event Tracing
(ETW).
🔹 Attack Chain Analysis
1. Initial Access (LNK): User opens Cyber security.lnk from Discord —
triggers hidden PowerShell (MITRE: T1204.002).
2. Download/Stage: PowerShell extracts embedded PDF and Moq.zip into
Temp/Public\Nuget.
3. Execution via LOLBin: odbcconf.exe is used to load the dropped DLL
(MITRE: T1218 — System Binary Proxy Execution).
4. Persistence/Control: Malicious DLL implements RAT behaviors,
including remote commands and reconnaissance.
5. Defense Evasion: AMSI bypass and EtwEventWrite patching (Impair
Defenses) reduce telemetry and impede detection.
Detection guidance:
• Monitor process trees where odbcconf.exe is launched from atypical
parents (PowerShell/conhost).
• Alert on hidden PowerShell instances extracting embedded files and
writing PDFs from LNK streams.
• Watch for API patching attempts around EtwEventWrite and AMSI
initialization failures.
Mitigation:
• Restrict execution of unsigned Office/shortcut attachments from
untrusted channels.
• Apply application control to prevent odbcconf.exe from loading untrusted DLLs.
• Enable telemetry and harden AMSI where possible; monitor ETW integrity.
References/Notes: Preliminary detections were reported from Israel;
campaign observed distribution via Discord and use of decoy PDFs. #LNK
#RAT #AMSI #ETW #LOLBins
🔗 Source: https://labs.k7computing.com/index.php/from-lnk-to-rat-deep-dive-into-the-lnk-malware-infection-chain/