국내 금융 기업 및 보험사를 사칭한 CHM 악성코드
2023-07-20 • Ahnlab • CHM malware impersonating domestic financial companies and insurance companies •
ASEC describes CHM malware distributed in RAR archives while impersonating Korean financial firms and insurers with decoy help-window content about card limits, insurance withdrawals, and bank contracts. When opened, the CHM script decompiled files to C:\Users\Public\Libraries, executed Docs.jse with wscript, and used a Run-key entry for persistence. The script then launched PowerShell to download an additional payload as %tmp%\alg.exe from multiple attacker-controlled URLs, although the payload servers were unavailable during analysis. AhnLab classified the samples as Dropper/CHM.Generic and warned that the final payload could enable information theft or other follow-on activity depending on what was retrieved.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 01e7405ddd5545ffb4a57040acc4b6f… | 2023-07-20 | 2023-09-13 |
| HASH | f5e46e18facc6f8fde6658b96dcd379… | 2023-07-20 | 2023-09-13 |
| URL | https://atusay.lat/kxydo | 2023-07-20 | 2023-08-30 |
| DOMAIN | atusay.lat | 2023-07-20 | 2023-08-30 |
| URL | https://crilts.cfd/cdeeb | 2023-07-20 | 2023-08-25 |
| DOMAIN | crilts.cfd | 2023-07-20 | 2023-08-25 |
| HASH | fcfb0398eb0216332bb3ce25e5e353e… | 2023-07-20 | 2023-07-27 |
| HASH | eb21cf8e6f64340216e9c326fb58956… | 2023-07-20 | 2023-07-27 |
| URL | https://labimy.ink/rskme | 2023-07-20 | 2023-07-27 |
| URL | https://ppangz.mom/mjifi | 2023-07-20 | 2023-07-27 |
| DOMAIN | ppangz.mom | 2023-07-20 | 2023-07-27 |
| DOMAIN | labimy.ink | 2023-07-20 | 2023-07-27 |