김수키(Kimsuky) 만든 SGI 서울보증 사칭 악성코드-sgic_info.chm(2023.8.14)
2023-08-21 • Sakai • SGI Seoul Guarantee impersonation malware created by Kimsuky - sgic_info.chm (2023.8.14) •
A Korean malware analysis attributes an SGI Seoul Guarantee-themed CHM lure, sgic_info.chm, to Kimsuky and describes it as a fake insurance-contract notice likely aimed at a Korean logistics-related target. The CHM uses hh.exe to decompile content under C:\Users\Public\Libraries, drops Docs.jse and a decoy sgic_info.html, and runs wscript to continue execution. The JScript applies character substitution/rotation obfuscation, writes persistence-related registry data, and launches PowerShell to download alg.exe from drimby.top/wndfi. The source provides hashes for the CHM and dropped files, making the report useful for tracking Kimsuky CHM-lure tradecraft and associated infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b0bed133fa08e36d05f0361aefa5cbd1 | 2023-08-21 | 2023-08-21 |
| HASH | 4474f7c8b1ee45d868e201de900f6a3… | 2023-08-21 | 2023-08-21 |
| HASH | 5071a29f42689c6d83de6fc16bbc627… | 2023-08-21 | 2023-08-21 |
| HASH | 793ae915ab19520cb3508630b51e289e | 2023-08-21 | 2023-08-21 |
| HASH | 548e6a6d4c349b36b6f46949ac7e6e3b | 2023-08-21 | 2023-08-21 |
| HASH | 4cc6398973af2a0041283357cee19245 | 2023-08-21 | 2023-08-21 |
| URL | https://drimby.top/wndfi | 2023-08-01 | 2023-08-21 |
| DOMAIN | drimby.top | 2023-08-01 | 2023-08-21 |