북한 해킹 단체 APT37 에서 만든 악성코드-국군재정관리단.chm(2023.11.21)

2023-12-04 Sakai Malware created by North Korean hacking group APT37 - Armed Forces Financial Management Group.chm (2023.11.21)

https://wezard4u.tistory.com/6672

Thumbnail for 북한 해킹 단체 APT37 에서 만든 악성코드-국군재정관리단.chm(2023.11.21)

The write-up analyzes an APT37 CHM malware sample themed around South Korea's Armed Forces Financial Management Corps, suggesting a lure aimed at military finance personnel. The sample uses HTML Help content to invoke mshta.exe and contact attiferstudio.com under an install.bak path, then shows a fake encrypted-mail prompt asking for the first six digits of a resident registration number. The source lists hashes for the CHM sample and notes that the remote site returned 404 during the author's check, so the final downloaded payload could not be confirmed from that URL. Vendor detections classify the file as CHM, HTML, JavaScript, or Trojan downloader malware, including ScarCruft-related naming from some engines.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN dhl.com 2023-09-26 2025-08-29
HASH a372e8dfd1940ef4f9e74095a8bf3bd7 2023-03-21 2024-02-16
HASH e73d679ca6314946072c41dcbbf59dc… 2023-12-04 2023-12-04
URL http://attiferstudio.com/instal… 2023-12-04 2023-12-04
URL http://attiferstudio.com/ 2023-12-04 2023-12-04
HASH 3d2738ff73af2bc88cb9c396b31f699… 2023-03-16 2023-12-04
DOMAIN attiferstudio.com 2023-03-16 2023-12-04

Related Actors

Related Reports

« Back