패스워드 파일로 위장하여 유포 중인 악성코드
2023-03-10 • Ahnlab • Malware distributed disguised as a password file •
AhnLab reports Korean-targeted malware distributed in archives that pair password-protected legitimate documents with files masquerading as password information. One CHM variant is assessed as likely tied to RedEyes/APT37/ScarCruft because it reuses commands seen in the group’s M2RAT persistence flow, launching mshta to fetch scripts and register Run-key persistence. The CHM samples contact infrastructure such as shacc.kr and 141.105.65.165 to receive commands and return Base64-encoded results, while a separate LNK variant drops a password text file and VBS script that retrieves additional code from hondes.getenjoyment.net. The report highlights continued abuse of CHM and LNK lures to make victims open malicious helper files alongside benign documents.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://hondes.getenjoyment.net/… | 2023-03-10 | 2024-09-05 |
| DOMAIN | hondes.getenjoyment.net | 2023-03-10 | 2024-09-05 |
| HASH | 809528921de39530de59e3793d74af98 | 2023-03-10 | 2023-03-21 |
| URL | http://shacc.kr/skin/product/1.… | 2023-03-03 | 2023-03-21 |
| DOMAIN | shacc.kr | 2023-03-03 | 2023-03-21 |
| IPv4 | 141.105.65.165 | 2023-03-10 | 2023-03-16 |
| HASH | 2b79e2bd6548118c942480a52b5a1669 | 2023-03-10 | 2023-03-10 |
| HASH | b39182a535f41699280ca088eef0f258 | 2023-03-10 | 2023-03-10 |