북한 해킹단체 김수키(Kimsuky)에서 만든 금융거래확인서로 위장한 악성코드-confirmation.chm(2024.12.10)
2024-12-20 • Sakai • Kimsuky malware disguised as a financial transaction confirmation document (confirmation.chm) •
A Korean-language analysis attributes a malicious Windows CHM help file named confirmation.chm to Kimsuky and describes it as disguised as a financial transaction confirmation document. The file executes openCI.vbs from C:\Users\Public\Libraries, shows a decoy image to the user, and uses batch scripts to register persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The scripts collect system information, process listings, and Desktop and Downloads directory listings, then send staged data to hxxps://nasweir[.]com and request additional content through an out.php endpoint using the Base64-encoded computer name. The excerpt provides hashes for the CHM sample, including SHA-256 e6bcdb402999f6f35351c0b9a1be84345aea88c3f662ba27341d7857aeb8cc39, making the case useful for detecting Kimsuky CHM lures and script-based Windows staging.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e6bcdb402999f6f35351c0b9a1be843… | 2024-12-20 | 2024-12-20 |
| HASH | 38032503b59125fb464e1b7aaa449d3… | 2024-12-20 | 2024-12-20 |
| HASH | 08b4bcee92417560d61c5f29649cdfad | 2024-12-20 | 2024-12-20 |
| URL | https://nasweir.com | 2024-12-20 | 2024-12-20 |
| DOMAIN | nasweir.com | 2024-12-20 | 2024-12-20 |