문서 편집 및 메신저 프로그램으로 위장한 백도어 (*.chm)
2022-05-03 • Ahnlab • Backdoor disguised as a document editing and messenger program (*.chm) •
ASEC observed malicious CHM files distributed in South Korea with filenames tailored to national institution administrators and university professors, including electronic attendance and faculty workload manual themes. The CHM script decompiled and ran ImagingDevices.exe to side-load a malicious DLL, which dropped a VBE ReVBShell backdoor capable of contacting C2 and executing attacker commands while avoiding activity when ESET Security was detected. Follow-on payloads masqueraded as Hancom Office and KakaoTalk processes, including HimTraylcon.exe as a backdoor, KaKaoTalk.exe as BrowserPasswordDump, and HNetComAgent.exe as a keylogger writing encoded logs under C:\Windows\Tasks. Reported infrastructure included formsgle.freedynamicdns[.]net:8080, finance.my-homeip[.]com:443, and hxxps://92.38.135[.]212/fuat/HimTraylcon.exe, showing a phishing-to-backdoor chain aimed at credential theft and further compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c3d34480c38e69cf585f1e645445a9d5 | 2022-05-03 | 2022-05-03 |
| HASH | efb242e03a435dff4e253a5259a2324e | 2022-05-03 | 2022-05-03 |
| HASH | 29b0818d2e374d7b86937a952975ab14 | 2022-05-03 | 2022-05-03 |
| HASH | 87e2fc68014bbedc41449e6835ec516a | 2022-05-03 | 2022-05-03 |
| DOMAIN | formsgle.freedynamicdns.net | 2022-05-03 | 2022-05-03 |
| DOMAIN | finance.my-homeip.com | 2022-05-03 | 2022-05-03 |
| IPv4 | 92.38.135.212 | 2022-05-03 | 2022-05-03 |