CHM 악성코드에서 확인된 안티 샌드박스 및 기업 타겟 공격
2022-06-07 • Ahnlab • Anti-sandbox and enterprise-targeted attacks identified in CHM malware •
AhnLab ASEC identified two CHM malware variants circulating in South Korea: one using anti-sandbox checks and another designed to avoid execution on consumer V3Lite systems while targeting enterprise environments. The anti-sandbox variant drops a malicious VBE only after checking the TEMP folder file count and confirming the expected DLL-hijacking process name, then registers itself under the Windows Run key. The enterprise-targeted variant creates and runs chmext.exe under ProgramData and exits if the V3Lite process is present, indicating selective execution against non-consumer environments. The report highlights CHM-based delivery, DLL hijacking, ReVBShell execution and environment-aware evasion as practical obstacles for sandbox analysis and endpoint detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 210db61d1b11c1d233fd8a0645946074 | 2022-04-11 | 2022-08-30 |
| HASH | e33114a7894a1a284084861eee5f9975 | 2022-06-07 | 2022-06-07 |
| HASH | bb71af5c5a113a050ff5928535d3465e | 2022-06-07 | 2022-06-07 |
| HASH | 95d914d34e9cb5bd2e5db411ed5345b9 | 2022-06-07 | 2022-06-07 |
| HASH | 619649ce3fc1682c702d9159e778f8fd | 2022-04-11 | 2022-06-07 |