북한 해킹 단체 김수키(Kimsuky) 에서 만든 240903-회국회(정) 제1차 전체회의 의사일정안(결산,안건 상정,현안 보고)2024.8.1
2024-08-13 • Sakai • Malware Created by the North Korean Hacking Group Kimsuky - 240903 National Assembly First Plenary Meeting Agenda (Settlement, Agenda Submission, Current Issues Report) (2024.8.1) •
A Kimsuky-attributed CHM lure masqueraded as a South Korean National Assembly committee meeting schedule, suggesting targeting of lawmakers, legislative aides, or related personnel. The sample displayed garbled visible content while embedded HTML and CHM ActiveX-style shortcut logic launched PowerShell commands in the background. The script copied a matching temporary file into the user’s AppData directory as Helpstore.exe, created a scheduled task named MicrosoftEdgeUpdateTask to run it one minute later, and loaded a hidden iframe pointing to checker.jetos.com. The excerpt provides hashes for the CHM file, Helpstore.exe, and index.html, and multiple security products detected the sample as a CHM downloader, HTML agent, dropper, or related Windows Trojan.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 86ef578ca5923119e65049f3d26bff7… | 2024-08-13 | 2024-08-13 |
| HASH | 3e0f4eaf3db754160f8c012a94772bf… | 2024-08-13 | 2024-08-13 |
| HASH | e7197bb5c5363b56a1e33f333e6613f… | 2024-08-13 | 2024-08-13 |
| HASH | f5f5a585a12df9cb406dde6b3e6da23d | 2024-08-13 | 2024-08-13 |
| HASH | f00852dab6c6540bb6700d4e6ec43d6… | 2024-08-13 | 2024-08-13 |
| URL | http://checker.jetos.com/l/siCT… | 2024-08-13 | 2024-08-13 |
| DOMAIN | checker.jetos.com | 2024-08-13 | 2024-08-13 |