북한 해킹단체 김수키(Kimsuky)에서 만든 금융거래확인서로 위장한 악성코드-confirmation.chm(2024.12.10)

2024-12-20 Sakai Kimsuky malware disguised as a financial transaction confirmation document (confirmation.chm)

https://wezard4u.tistory.com/429360

Thumbnail for 북한 해킹단체 김수키(Kimsuky)에서 만든 금융거래확인서로 위장한 악성코드-confirmation.chm(2024.12.10)

A Korean-language analysis attributes a malicious Windows CHM help file named confirmation.chm to Kimsuky and describes it as disguised as a financial transaction confirmation document. The file executes openCI.vbs from C:\Users\Public\Libraries, shows a decoy image to the user, and uses batch scripts to register persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The scripts collect system information, process listings, and Desktop and Downloads directory listings, then send staged data to hxxps://nasweir[.]com and request additional content through an out.php endpoint using the Base64-encoded computer name. The excerpt provides hashes for the CHM sample, including SHA-256 e6bcdb402999f6f35351c0b9a1be84345aea88c3f662ba27341d7857aeb8cc39, making the case useful for detecting Kimsuky CHM lures and script-based Windows staging.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e6bcdb402999f6f35351c0b9a1be843… 2024-12-20 2024-12-20
HASH 38032503b59125fb464e1b7aaa449d3… 2024-12-20 2024-12-20
HASH 08b4bcee92417560d61c5f29649cdfad 2024-12-20 2024-12-20
URL https://nasweir.com 2024-12-20 2024-12-20
DOMAIN nasweir.com 2024-12-20 2024-12-20

Related Actors

Related Reports

« Back