Kimsuky 그룹의 CHM 기반 정찰용 악성코드
2024-02-22 • Secu I • Kimsuky group CHM-based reconnaissance malware •
SECUI analyzes a Kimsuky reconnaissance malware variant that shifted delivery from earlier LNK files to a compiled HTML Help file. The CHM lure appears to contain Bitcoin key themed content and executes embedded scripts through hh.exe, decompiling files into C:\ProgramData\WindowsSystemDeviceManager before launching tsmgr.vbs. The script registers an hourly scheduled task named SystemDeviceUpdate to run AppXml.dat, removes staging files, and contacts https://lfpa.website/pkg/qsuw.php with the value 34689 to retrieve additional script code. The follow on script changes Internet Explorer and Edge related registry settings, showing Kimsuky's continued use of lightweight script based reconnaissance chains for staging later activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | lfpa.website | 2024-02-22 | 2025-01-02 |
| HASH | 35ddb63c0729a7e3019c026865ea195… | 2024-02-22 | 2024-11-20 |
| URL | https://lfpa.website/pkg/qsuw.p… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg/djqxfh… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg/qsuw.p… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg/show.p… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg/xyce.p… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg/xyce.p… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg/ilot.p… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg/qsuw.p… | 2024-02-22 | 2024-02-22 |
| URL | https://lfpa.website/pkg | 2024-02-22 | 2024-02-22 |
| IPv4 | 173.214.164.75 | 2024-02-22 | 2024-02-22 |