김수키(Kimsuky) 만든 chm 방식 악성코드-via.chm(2023.7.28)

2023-08-01 • Sakai • chm type malware created by Kimsuky - via.chm (2023.7.28) •

https://wezard4u.tistory.com/6527

Thumbnail for 김수키(Kimsuky) 만든 chm 방식 악성코드-via.chm(2023.7.28)

The source analyzes a Kimsuky-attributed CHM malware sample named via.chm that was described as built to target journalists. The CHM content abuses an ActiveX shortcut object and JavaScript to run hidden commands, write mini.dat, decode it into mini.vbs with certutil, and register persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The embedded PowerShell uses a spoofed browser User-Agent, contacts one.bandi.tokyo infrastructure, and contains routines for collecting and uploading data through multipart web requests. The article provides hashes for the sample and highlights the CHM-to-VBS-to-PowerShell chain as the key infection mechanism.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 510898ad9082dfc559aa511848c2946… 2023-08-01 2023-08-01
URL http://one.bandi.tokyo/clever/d… 2023-08-01 2023-08-01
URL http://one.bandi.tokyo/clever/s… 2023-08-01 2023-08-01
DOMAIN one.bandi.tokyo 2023-08-01 2023-08-01

Related Actors

Related Reports

« Back