김수키(Kimsuky) 등기필정부 및 등기완료 통지서로 위장한 악성코드-[HF].chm(2023.11.14)

2023-11-28 Sakai Malicious code disguised as Kimsuky's registration certificate and notification of registration completion - [HF].chm (2023.11.14)

https://wezard4u.tistory.com/6669

Thumbnail for 김수키(Kimsuky) 등기필정부 및 등기완료 통지서로 위장한 악성코드-[HF].chm(2023.11.14)

The source analyzes a Korean-language CHM malware sample assessed by the author as likely Kimsuky activity, disguised as real-estate registration information and a registration completion notice. The CHM launches VBScript that starts a hidden batch file, registers a scheduled task named SafeBrowsing, and repeatedly executes supporting VBS and BAT components for persistence. The scripts contact niscarea.com with the victim computer name Base64-encoded in a query string, then use PowerShell and staged batch logic to download and run additional payloads from a ZIP workflow. Representative hashes include MD5 f35b05779e9538cec363ca37ab38e287 and SHA-256 da79eea1198a1a10e2ffd50fd949521632d8f252fb1aadb57a45218482b9fd89.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://niscarea.com 2023-11-28 2024-12-27
DOMAIN niscarea.com 2023-11-28 2024-12-27
HASH d4fa57f9c9e35222a8cacddc79055c1… 2023-11-28 2024-03-20
HASH da79eea1198a1a10e2ffd50fd949521… 2023-11-28 2024-03-20
HASH f35b05779e9538cec363ca37ab38e287 2023-11-28 2024-03-20

Related Actors

Related Reports

« Back