대북 관련 질문지를 위장한 CHM 악성코드 (Kimsuky)

2023-03-08 Ahnlab CHM malware disguised as a North Korea-related questionnaire (Kimsuky)

https://asec.ahnlab.com/ko/48960/

Thumbnail for 대북 관련 질문지를 위장한 CHM 악성코드 (Kimsuky)

AhnLab ASEC reported CHM malware assessed as Kimsuky activity, distributed in password-protected archives after the recipient responded to an email posing as a North Korea-related interview request. Running the CHM opened a decoy questionnaire while a Shortcut object executed commands that wrote an encoded payload to Document.dat, decoded it with certutil into Document.vbs, and registered the script under the HKCU Run key for persistence. Document.vbs attempted to load a PowerShell script from mpevalr.ria[.]monster and the recovered script performed keylogging, clipboard collection, and exfiltration to /SmtInfo/show.php. The activity matches previously reported Kimsuky CHM and document-based phishing tradecraft, with representative hashes and the mpevalr.ria[.]monster URLs provided as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 726af41024d06df195784ae88f2849e4 2023-03-08 2023-05-24
HASH 89c0e93813d3549efe7274a0b9597f6f 2023-03-08 2023-03-08
HASH 9f560c90b7ba6f02233094ed03d9272e 2023-03-08 2023-03-08
HASH 0f41d386e30e9f5ae5be4a707823fd78 2023-03-08 2023-03-08
URL http://mpevalr.ria.monster/SmtI… 2023-03-08 2023-03-08
URL http://mpevalr.ria.monster/SmtI… 2023-03-08 2023-03-08
DOMAIN mpevalr.ria.monster 2023-03-08 2023-03-08

Related Actors

Related Reports

« Back