대북 관련 질문지를 위장한 CHM 악성코드 (Kimsuky)
2023-03-08 • Ahnlab • CHM malware disguised as a North Korea-related questionnaire (Kimsuky) •
AhnLab ASEC reported CHM malware assessed as Kimsuky activity, distributed in password-protected archives after the recipient responded to an email posing as a North Korea-related interview request. Running the CHM opened a decoy questionnaire while a Shortcut object executed commands that wrote an encoded payload to Document.dat, decoded it with certutil into Document.vbs, and registered the script under the HKCU Run key for persistence. Document.vbs attempted to load a PowerShell script from mpevalr.ria[.]monster and the recovered script performed keylogging, clipboard collection, and exfiltration to /SmtInfo/show.php. The activity matches previously reported Kimsuky CHM and document-based phishing tradecraft, with representative hashes and the mpevalr.ria[.]monster URLs provided as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 726af41024d06df195784ae88f2849e4 | 2023-03-08 | 2023-05-24 |
| HASH | 89c0e93813d3549efe7274a0b9597f6f | 2023-03-08 | 2023-03-08 |
| HASH | 9f560c90b7ba6f02233094ed03d9272e | 2023-03-08 | 2023-03-08 |
| HASH | 0f41d386e30e9f5ae5be4a707823fd78 | 2023-03-08 | 2023-03-08 |
| URL | http://mpevalr.ria.monster/SmtI… | 2023-03-08 | 2023-03-08 |
| URL | http://mpevalr.ria.monster/SmtI… | 2023-03-08 | 2023-03-08 |
| DOMAIN | mpevalr.ria.monster | 2023-03-08 | 2023-03-08 |