문서 편집 및 메신저 프로그램으로 위장한 백도어 (*.chm)

2022-05-03 Ahnlab Backdoor disguised as a document editing and messenger program (*.chm)

https://asec.ahnlab.com/ko/33948/

Thumbnail for 문서 편집 및 메신저 프로그램으로 위장한 백도어 (*.chm)

ASEC observed malicious CHM files distributed in South Korea with filenames tailored to national institution administrators and university professors, including electronic attendance and faculty workload manual themes. The CHM script decompiled and ran ImagingDevices.exe to side-load a malicious DLL, which dropped a VBE ReVBShell backdoor capable of contacting C2 and executing attacker commands while avoiding activity when ESET Security was detected. Follow-on payloads masqueraded as Hancom Office and KakaoTalk processes, including HimTraylcon.exe as a backdoor, KaKaoTalk.exe as BrowserPasswordDump, and HNetComAgent.exe as a keylogger writing encoded logs under C:\Windows\Tasks. Reported infrastructure included formsgle.freedynamicdns[.]net:8080, finance.my-homeip[.]com:443, and hxxps://92.38.135[.]212/fuat/HimTraylcon.exe, showing a phishing-to-backdoor chain aimed at credential theft and further compromise.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c3d34480c38e69cf585f1e645445a9d5 2022-05-03 2022-05-03
HASH efb242e03a435dff4e253a5259a2324e 2022-05-03 2022-05-03
HASH 29b0818d2e374d7b86937a952975ab14 2022-05-03 2022-05-03
HASH 87e2fc68014bbedc41449e6835ec516a 2022-05-03 2022-05-03
DOMAIN formsgle.freedynamicdns.net 2022-05-03 2022-05-03
DOMAIN finance.my-homeip.com 2022-05-03 2022-05-03
IPv4 92.38.135.212 2022-05-03 2022-05-03

Related Reports

« Back