Malware
HOTWAX
HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file.
HOTWAX is a Windows malware family operated by Lazarus Group.
Background
HOTWAX is a module that, on launch, resolves the system API functions it requires and then locates a .CHM file. Using the Spritz algorithm together with a hard-coded key, it decrypts a payload, identifies the target process, and tries to inject the decrypted module extracted from the CHM file into that process's address space.
Source: Malpedia (Fraunhofer FKIE).