CHM 악성코드에서 확인된 안티 샌드박스 및 기업 타겟 공격
2022-06-07 • Ahnlab • Anti-sandbox and enterprise-targeted attacks identified in CHM malware •
AhnLab ASEC identified two CHM malware variants circulating in South Korea: one using anti-sandbox checks and another designed to avoid execution on consumer V3Lite systems while targeting enterprise environments. The anti-sandbox variant drops a malicious VBE only after checking the TEMP folder file count and confirming the expected DLL-hijacking process name, then registers itself under the Windows Run key. The enterprise-targeted variant creates and runs chmext.exe under ProgramData and exits if the V3Lite process is present, indicating selective execution against non-consumer environments. The report highlights CHM-based delivery, DLL hijacking, ReVBShell execution and environment-aware evasion as practical obstacles for sandbox analysis and endpoint detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 74f78f4751886b1311e7387f1e3bcf5… | 2022-04-11 | 2022-08-30 |
| HASH | e1748e7e668d6fc7772e95c08d32f41… | 2022-06-07 | 2022-06-07 |
| HASH | 607f324c3427916d67369e40af72aa4… | 2022-06-07 | 2022-06-07 |
| HASH | 042ce8c91c6bc7eeb32e0df4ca95f49… | 2022-04-11 | 2022-06-07 |
| HASH | 94b4e20ead4fefe11519b00f6eac9f6… | 2022-04-11 | 2022-06-07 |