CHM Impersonates Korean Financial Institutes and Insurance Companies

2023-07-27 • Ahnlab •

https://asec.ahnlab.com/en/55569/

Thumbnail for CHM Impersonates Korean Financial Institutes and Insurance Companies

AhnLab ASEC reported CHM malware distributed in RAR archives that impersonated Korean financial institutions and insurance companies with themes such as credit-card limits, insurance-fee withdrawal results, and banking contracts. When opened, the CHM decompiled content under C:\Users\Public\Libraries and executed an encoded Docs.jse script through wscript. The script added persistence through the Run key and used PowerShell to download an additional payload as %tmp%\alg.exe from actor-controlled URLs such as ppangz[.]mom and crilts[.]cfd. ASEC warned that the downloaded malware could perform follow-on actions including information theft, making the lure set a targeted Korean social-engineering and downloader threat.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 01e7405ddd5545ffb4a57040acc4b6f… 2023-07-20 2023-09-13
HASH f5e46e18facc6f8fde6658b96dcd379… 2023-07-20 2023-09-13
URL https://atusay.lat/kxydo 2023-07-20 2023-08-30
DOMAIN atusay.lat 2023-07-20 2023-08-30
URL https://crilts.cfd/cdeeb 2023-07-20 2023-08-25
DOMAIN crilts.cfd 2023-07-20 2023-08-25
HASH fcfb0398eb0216332bb3ce25e5e353e… 2023-07-20 2023-07-27
HASH eb21cf8e6f64340216e9c326fb58956… 2023-07-20 2023-07-27
URL https://labimy.ink/rskme 2023-07-20 2023-07-27
URL https://ppangz.mom/mjifi 2023-07-20 2023-07-27
DOMAIN ppangz.mom 2023-07-20 2023-07-27
DOMAIN labimy.ink 2023-07-20 2023-07-27

Related Actors

Related Reports

« Back