김수키(Kimsuky) 만든 SGI 서울보증 사칭 악성코드-sgic_info.chm(2023.8.14)
2023-08-21 • Sakai • SGI Seoul Guarantee impersonation malware created by Kimsuky - sgic_info.chm (2023.8.14) •
A Korean malware analysis attributes an SGI Seoul Guarantee-themed CHM lure, sgic_info.chm, to Kimsuky and describes it as a fake insurance-contract notice likely aimed at a Korean logistics-related target. The CHM uses hh.exe to decompile content under C:\Users\Public\Libraries, drops Docs.jse and a decoy sgic_info.html, and runs wscript to continue execution. The JScript applies character substitution/rotation obfuscation, writes persistence-related registry data, and launches PowerShell to download alg.exe from drimby.top/wndfi. The source provides hashes for the CHM and dropped files, making the report useful for tracking Kimsuky CHM-lure tradecraft and associated infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5071a29f42689c6d83de6fc16bbc627… | 2023-08-21 | 2023-08-21 |
| HASH | 35329fdadfeeb2377d06e27515a597b… | 2023-08-21 | 2023-08-21 |
| HASH | 9d095f0d130605af1aa63e0c934ad92… | 2023-08-21 | 2023-08-21 |
| HASH | abe6cd96b2035891f362e486a170935… | 2023-08-21 | 2023-08-21 |
| URL | https://drimby.top/wndfi | 2023-08-01 | 2023-08-21 |
| DOMAIN | drimby.top | 2023-08-01 | 2023-08-21 |