다양한 주제를 이용하여 CHM 악성코드를 유포 중인 Kimsuky
2023-06-16 • Ahnlab • Kimsuky is spreading CHM malware using various topics. •
AhnLab describes a May 2023 Kimsuky campaign that increasingly used CHM help files rather than ordinary document lures, with themes tailored to Korean targets such as tax filings, financial transactions, cryptocurrency records, contracts, certificates, and order sheets. The CHM files displayed normal-looking help windows while embedded script commands wrote encoded data under the user Links folder, decoded VBS/BAT components with certutil, registered persistence in the Run key, and launched a runner chain. The downloaded BAT and CAB components collected user information, sent it with the computer name to hxxp://vndjgheruewy1[.]com/uun06/uwpp.php, and repeatedly checked for target-specific additional payloads named with the infected PC name. The activity shows Kimsuky using stolen personal information and selective follow-on malware delivery to make CHM-based APT attacks more targeted.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ae6fdb8945991b587ab790c2121345ce | 2023-06-16 | 2023-06-21 |
| HASH | 075160d6c8d82b96d1ae7893761695a6 | 2023-06-16 | 2023-06-21 |
| HASH | d62dcb76fa0fb4b725ea9c8643874ae7 | 2023-06-16 | 2023-06-21 |
| HASH | 98764ae00cee9f2cc87530601c159387 | 2023-06-16 | 2023-06-21 |
| HASH | 9861999409cdbc1f7c4c1079d348697c | 2023-06-16 | 2023-06-21 |
| HASH | ef58a1326b98feccc90c4d37a8ce2fe2 | 2023-06-16 | 2023-06-21 |
| HASH | b5a873ee6b839cbd03789115fc3ae944 | 2023-06-16 | 2023-06-21 |
| HASH | e5b0430290dc71193b7ea2fc829a9910 | 2023-06-16 | 2023-06-21 |
| HASH | e9e56ee78e019e09d5dbe0bb373adf09 | 2023-06-16 | 2023-06-21 |
| HASH | 7c7b8dd6dd4ba7b443e84287671f0e79 | 2023-06-16 | 2023-06-21 |
| URL | http://vndjgheruewy1.com/tnd/pu… | 2023-06-16 | 2023-06-21 |
| URL | http://vndjgheruewy1.com/jun06/… | 2023-06-16 | 2023-06-21 |
| URL | http://vndjgheruewy1.com/tnd/qu… | 2023-06-16 | 2023-06-21 |
| URL | http://vndjgheruewy1.com/uun06/… | 2023-06-16 | 2023-06-21 |
| DOMAIN | vndjgheruewy1.com | 2023-06-16 | 2023-06-21 |