북한 해킹 단체 APT37 에서 만든 악성코드-국군재정관리단.chm(2023.11.21)
2023-12-04 • Sakai • Malware created by North Korean hacking group APT37 - Armed Forces Financial Management Group.chm (2023.11.21) •
The write-up analyzes an APT37 CHM malware sample themed around South Korea's Armed Forces Financial Management Corps, suggesting a lure aimed at military finance personnel. The sample uses HTML Help content to invoke mshta.exe and contact attiferstudio.com under an install.bak path, then shows a fake encrypted-mail prompt asking for the first six digits of a resident registration number. The source lists hashes for the CHM sample and notes that the remote site returned 404 during the author's check, so the final downloaded payload could not be confirmed from that URL. Vendor detections classify the file as CHM, HTML, JavaScript, or Trojan downloader malware, including ScarCruft-related naming from some engines.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | dhl.com | 2023-09-26 | 2025-08-29 |
| HASH | a372e8dfd1940ef4f9e74095a8bf3bd7 | 2023-03-21 | 2024-02-16 |
| HASH | e73d679ca6314946072c41dcbbf59dc… | 2023-12-04 | 2023-12-04 |
| URL | http://attiferstudio.com/instal… | 2023-12-04 | 2023-12-04 |
| URL | http://attiferstudio.com/ | 2023-12-04 | 2023-12-04 |
| HASH | 3d2738ff73af2bc88cb9c396b31f699… | 2023-03-16 | 2023-12-04 |
| DOMAIN | attiferstudio.com | 2023-03-16 | 2023-12-04 |