CHM 악성코드에서 확인된 안티 샌드박스 및 기업 타겟 공격

2022-06-07 • Ahnlab • Anti-sandbox and enterprise-targeted attacks identified in CHM malware •

https://asec.ahnlab.com/ko/35072/

Thumbnail for CHM 악성코드에서 확인된 안티 샌드박스 및 기업 타겟 공격

AhnLab ASEC identified two CHM malware variants circulating in South Korea: one using anti-sandbox checks and another designed to avoid execution on consumer V3Lite systems while targeting enterprise environments. The anti-sandbox variant drops a malicious VBE only after checking the TEMP folder file count and confirming the expected DLL-hijacking process name, then registers itself under the Windows Run key. The enterprise-targeted variant creates and runs chmext.exe under ProgramData and exits if the V3Lite process is present, indicating selective execution against non-consumer environments. The report highlights CHM-based delivery, DLL hijacking, ReVBShell execution and environment-aware evasion as practical obstacles for sandbox analysis and endpoint detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 74f78f4751886b1311e7387f1e3bcf5… 2022-04-11 2022-08-30
HASH e1748e7e668d6fc7772e95c08d32f41… 2022-06-07 2022-06-07
HASH 607f324c3427916d67369e40af72aa4… 2022-06-07 2022-06-07
HASH 042ce8c91c6bc7eeb32e0df4ca95f49… 2022-04-11 2022-06-07
HASH 94b4e20ead4fefe11519b00f6eac9f6… 2022-04-11 2022-06-07

Related Reports

« Back