김수키(Kimsuky) 만든 chm 방식 악성코드-via.chm(2023.7.28)

2023-08-01 Sakai chm type malware created by Kimsuky - via.chm (2023.7.28)

https://wezard4u.tistory.com/6527

Thumbnail for 김수키(Kimsuky) 만든 chm 방식 악성코드-via.chm(2023.7.28)

The source analyzes a Kimsuky-attributed CHM malware sample named via.chm that was described as built to target journalists. The CHM content abuses an ActiveX shortcut object and JavaScript to run hidden commands, write mini.dat, decode it into mini.vbs with certutil, and register persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The embedded PowerShell uses a spoofed browser User-Agent, contacts one.bandi.tokyo infrastructure, and contains routines for collecting and uploading data through multipart web requests. The article provides hashes for the sample and highlights the CHM-to-VBS-to-PowerShell chain as the key infection mechanism.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 510898ad9082dfc559aa511848c2946… 2023-08-01 2023-08-01
HASH 0c2a7c8be354638a9f7aa876c110c74… 2023-08-01 2023-08-01
HASH 5fe80f1b1e90815886a0553f2c322cc7 2023-08-01 2023-08-01
URL http://one.bandi.tokyo/clever/d… 2023-08-01 2023-08-01
URL http://one.bandi.tokyo/clever/s… 2023-08-01 2023-08-01
DOMAIN one.bandi.tokyo 2023-08-01 2023-08-01

Related Actors

Related Reports

« Back