김수키(Kimsuky) 만든 SGI 서울보증 사칭 악성코드-sgic_info.chm(2023.8.14)

2023-08-21 • Sakai • SGI Seoul Guarantee impersonation malware created by Kimsuky - sgic_info.chm (2023.8.14) •

https://wezard4u.tistory.com/6552

Thumbnail for 김수키(Kimsuky) 만든 SGI 서울보증 사칭 악성코드-sgic_info.chm(2023.8.14)

A Korean malware analysis attributes an SGI Seoul Guarantee-themed CHM lure, sgic_info.chm, to Kimsuky and describes it as a fake insurance-contract notice likely aimed at a Korean logistics-related target. The CHM uses hh.exe to decompile content under C:\Users\Public\Libraries, drops Docs.jse and a decoy sgic_info.html, and runs wscript to continue execution. The JScript applies character substitution/rotation obfuscation, writes persistence-related registry data, and launches PowerShell to download alg.exe from drimby.top/wndfi. The source provides hashes for the CHM and dropped files, making the report useful for tracking Kimsuky CHM-lure tradecraft and associated infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5071a29f42689c6d83de6fc16bbc627… 2023-08-21 2023-08-21
HASH 35329fdadfeeb2377d06e27515a597b… 2023-08-21 2023-08-21
HASH 9d095f0d130605af1aa63e0c934ad92… 2023-08-21 2023-08-21
HASH abe6cd96b2035891f362e486a170935… 2023-08-21 2023-08-21
URL https://drimby.top/wndfi 2023-08-01 2023-08-21
DOMAIN drimby.top 2023-08-01 2023-08-21

Related Actors

Related Reports

« Back