윈도우 도움말 파일(*.chm)로 유포되는 APT 공격
2022-03-17 • Ahnlab • APT Attack Distributed via Windows Help File (*.chm) •
AhnLab observed malicious Windows Help files distributed to South Korean users inside compressed email attachments alongside document files, with CHM execution triggering hidden script creation and follow-on download activity. The CHM files displayed legitimate-looking help content while using embedded HTML shortcut execution to write Document.dat and Document.vbs under the user profile Links directory. The VBS payload established persistence through HKCU Run and used PowerShell to download advupdate.exe from attacker-controlled URLs, although the currently fetched file was described as benign at analysis time. Related archive names and lures included court submission materials, contracts, wages, and game-server development help content, with infrastructure such as encorpost.com, nhn-games.com, sktelecom.help, and want-helper.com. The excerpt does not support DPRK attribution, but it documents an APT-style delivery chain abusing CHM files, social engineering, persistence, and staged executable download.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://encorpost.com/post/post… | 2022-03-17 | 2022-03-17 |
| URL | https://sktelecom.help/download… | 2022-03-17 | 2022-03-17 |
| URL | https://want-helper.com/databas… | 2022-03-17 | 2022-03-17 |
| URL | https://nhn-games.com/game03953… | 2022-03-17 | 2022-03-17 |
| URL | https://sktelecom.help/download… | 2022-03-17 | 2022-03-17 |
| URL | https://mage.github.io/mage/ | 2022-03-17 | 2022-03-17 |
| DOMAIN | encorpost.com | 2022-03-17 | 2022-03-17 |
| DOMAIN | nhn-games.com | 2022-03-17 | 2022-03-17 |
| DOMAIN | sktelecom.help | 2022-03-17 | 2022-03-17 |
| DOMAIN | want-helper.com | 2022-03-17 | 2022-03-17 |
| DOMAIN | mage.github.io | 2022-03-17 | 2022-03-17 |