CHM 악성코드에서 확인된 안티 샌드박스 및 기업 타겟 공격

2022-06-07 Ahnlab Anti-sandbox and enterprise-targeted attacks identified in CHM malware

https://asec.ahnlab.com/ko/35072/

Thumbnail for CHM 악성코드에서 확인된 안티 샌드박스 및 기업 타겟 공격

AhnLab ASEC identified two CHM malware variants circulating in South Korea: one using anti-sandbox checks and another designed to avoid execution on consumer V3Lite systems while targeting enterprise environments. The anti-sandbox variant drops a malicious VBE only after checking the TEMP folder file count and confirming the expected DLL-hijacking process name, then registers itself under the Windows Run key. The enterprise-targeted variant creates and runs chmext.exe under ProgramData and exits if the V3Lite process is present, indicating selective execution against non-consumer environments. The report highlights CHM-based delivery, DLL hijacking, ReVBShell execution and environment-aware evasion as practical obstacles for sandbox analysis and endpoint detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 210db61d1b11c1d233fd8a0645946074 2022-04-11 2022-08-30
HASH e33114a7894a1a284084861eee5f9975 2022-06-07 2022-06-07
HASH bb71af5c5a113a050ff5928535d3465e 2022-06-07 2022-06-07
HASH 95d914d34e9cb5bd2e5db411ed5345b9 2022-06-07 2022-06-07
HASH 619649ce3fc1682c702d9159e778f8fd 2022-04-11 2022-06-07

Related Reports

« Back