김수키(Kimsuky) 등기필정부 및 등기완료 통지서로 위장한 악성코드-[HF].chm(2023.11.14)
2023-11-28 • Sakai • Malicious code disguised as Kimsuky's registration certificate and notification of registration completion - [HF].chm (2023.11.14) •
The source analyzes a Korean-language CHM malware sample assessed by the author as likely Kimsuky activity, disguised as real-estate registration information and a registration completion notice. The CHM launches VBScript that starts a hidden batch file, registers a scheduled task named SafeBrowsing, and repeatedly executes supporting VBS and BAT components for persistence. The scripts contact niscarea.com with the victim computer name Base64-encoded in a query string, then use PowerShell and staged batch logic to download and run additional payloads from a ZIP workflow. Representative hashes include MD5 f35b05779e9538cec363ca37ab38e287 and SHA-256 da79eea1198a1a10e2ffd50fd949521632d8f252fb1aadb57a45218482b9fd89.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://niscarea.com | 2023-11-28 | 2024-12-27 |
| DOMAIN | niscarea.com | 2023-11-28 | 2024-12-27 |
| HASH | d4fa57f9c9e35222a8cacddc79055c1… | 2023-11-28 | 2024-03-20 |
| HASH | da79eea1198a1a10e2ffd50fd949521… | 2023-11-28 | 2024-03-20 |
| HASH | f35b05779e9538cec363ca37ab38e287 | 2023-11-28 | 2024-03-20 |