김수키(Kimsuky) 만든 SGI 서울보증 사칭 악성코드-sgic_info.chm(2023.8.14)

2023-08-21 Sakai SGI Seoul Guarantee impersonation malware created by Kimsuky - sgic_info.chm (2023.8.14)

https://wezard4u.tistory.com/6552

Thumbnail for 김수키(Kimsuky) 만든 SGI 서울보증 사칭 악성코드-sgic_info.chm(2023.8.14)

A Korean malware analysis attributes an SGI Seoul Guarantee-themed CHM lure, sgic_info.chm, to Kimsuky and describes it as a fake insurance-contract notice likely aimed at a Korean logistics-related target. The CHM uses hh.exe to decompile content under C:\Users\Public\Libraries, drops Docs.jse and a decoy sgic_info.html, and runs wscript to continue execution. The JScript applies character substitution/rotation obfuscation, writes persistence-related registry data, and launches PowerShell to download alg.exe from drimby.top/wndfi. The source provides hashes for the CHM and dropped files, making the report useful for tracking Kimsuky CHM-lure tradecraft and associated infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b0bed133fa08e36d05f0361aefa5cbd1 2023-08-21 2023-08-21
HASH 4474f7c8b1ee45d868e201de900f6a3… 2023-08-21 2023-08-21
HASH 5071a29f42689c6d83de6fc16bbc627… 2023-08-21 2023-08-21
HASH 793ae915ab19520cb3508630b51e289e 2023-08-21 2023-08-21
HASH 548e6a6d4c349b36b6f46949ac7e6e3b 2023-08-21 2023-08-21
HASH 4cc6398973af2a0041283357cee19245 2023-08-21 2023-08-21
URL https://drimby.top/wndfi 2023-08-01 2023-08-21
DOMAIN drimby.top 2023-08-01 2023-08-21

Related Actors

Related Reports

« Back