Kimsuky 그룹의 CHM 기반 정찰용 악성코드

2024-02-22 Secu I Kimsuky group CHM-based reconnaissance malware

https://stic.secui.com/main/main/threatInfo?id=209

Thumbnail for Kimsuky 그룹의 CHM 기반 정찰용 악성코드

SECUI analyzes a Kimsuky reconnaissance malware variant that shifted delivery from earlier LNK files to a compiled HTML Help file. The CHM lure appears to contain Bitcoin key themed content and executes embedded scripts through hh.exe, decompiling files into C:\ProgramData\WindowsSystemDeviceManager before launching tsmgr.vbs. The script registers an hourly scheduled task named SystemDeviceUpdate to run AppXml.dat, removes staging files, and contacts https://lfpa.website/pkg/qsuw.php with the value 34689 to retrieve additional script code. The follow on script changes Internet Explorer and Edge related registry settings, showing Kimsuky's continued use of lightweight script based reconnaissance chains for staging later activity.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN lfpa.website 2024-02-22 2025-01-02
HASH 35ddb63c0729a7e3019c026865ea195… 2024-02-22 2024-11-20
URL https://lfpa.website/pkg/qsuw.p… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg/djqxfh… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg/qsuw.p… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg/show.p… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg/xyce.p… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg/xyce.p… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg/ilot.p… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg/qsuw.p… 2024-02-22 2024-02-22
URL https://lfpa.website/pkg 2024-02-22 2024-02-22
IPv4 173.214.164.75 2024-02-22 2024-02-22

Related Actors

Related Reports

« Back