김수키(Kimsuky) 만든 chm 방식 악성코드-via.chm(2023.7.28)
2023-08-01 • Sakai • chm type malware created by Kimsuky - via.chm (2023.7.28) •
The source analyzes a Kimsuky-attributed CHM malware sample named via.chm that was described as built to target journalists. The CHM content abuses an ActiveX shortcut object and JavaScript to run hidden commands, write mini.dat, decode it into mini.vbs with certutil, and register persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The embedded PowerShell uses a spoofed browser User-Agent, contacts one.bandi.tokyo infrastructure, and contains routines for collecting and uploading data through multipart web requests. The article provides hashes for the sample and highlights the CHM-to-VBS-to-PowerShell chain as the key infection mechanism.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 510898ad9082dfc559aa511848c2946… | 2023-08-01 | 2023-08-01 |
| HASH | 0c2a7c8be354638a9f7aa876c110c74… | 2023-08-01 | 2023-08-01 |
| HASH | 5fe80f1b1e90815886a0553f2c322cc7 | 2023-08-01 | 2023-08-01 |
| URL | http://one.bandi.tokyo/clever/d… | 2023-08-01 | 2023-08-01 |
| URL | http://one.bandi.tokyo/clever/s… | 2023-08-01 | 2023-08-01 |
| DOMAIN | one.bandi.tokyo | 2023-08-01 | 2023-08-01 |