국내 금융 기업 및 보험사를 사칭한 CHM 악성코드

2023-07-20 • Ahnlab • CHM malware impersonating domestic financial companies and insurance companies •

https://asec.ahnlab.com/ko/55351/

Thumbnail for 국내 금융 기업 및 보험사를 사칭한 CHM 악성코드

ASEC describes CHM malware distributed in RAR archives while impersonating Korean financial firms and insurers with decoy help-window content about card limits, insurance withdrawals, and bank contracts. When opened, the CHM script decompiled files to C:\Users\Public\Libraries, executed Docs.jse with wscript, and used a Run-key entry for persistence. The script then launched PowerShell to download an additional payload as %tmp%\alg.exe from multiple attacker-controlled URLs, although the payload servers were unavailable during analysis. AhnLab classified the samples as Dropper/CHM.Generic and warned that the final payload could enable information theft or other follow-on activity depending on what was retrieved.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 01e7405ddd5545ffb4a57040acc4b6f… 2023-07-20 2023-09-13
HASH f5e46e18facc6f8fde6658b96dcd379… 2023-07-20 2023-09-13
URL https://atusay.lat/kxydo 2023-07-20 2023-08-30
DOMAIN atusay.lat 2023-07-20 2023-08-30
URL https://crilts.cfd/cdeeb 2023-07-20 2023-08-25
DOMAIN crilts.cfd 2023-07-20 2023-08-25
HASH fcfb0398eb0216332bb3ce25e5e353e… 2023-07-20 2023-07-27
HASH eb21cf8e6f64340216e9c326fb58956… 2023-07-20 2023-07-27
URL https://labimy.ink/rskme 2023-07-20 2023-07-27
URL https://ppangz.mom/mjifi 2023-07-20 2023-07-27
DOMAIN ppangz.mom 2023-07-20 2023-07-27
DOMAIN labimy.ink 2023-07-20 2023-07-27

Related Actors

Related Reports

« Back