CHM Impersonates Korean Financial Institutes and Insurance Companies
2023-07-27 • Ahnlab •
AhnLab ASEC reported CHM malware distributed in RAR archives that impersonated Korean financial institutions and insurance companies with themes such as credit-card limits, insurance-fee withdrawal results, and banking contracts. When opened, the CHM decompiled content under C:\Users\Public\Libraries and executed an encoded Docs.jse script through wscript. The script added persistence through the Run key and used PowerShell to download an additional payload as %tmp%\alg.exe from actor-controlled URLs such as ppangz[.]mom and crilts[.]cfd. ASEC warned that the downloaded malware could perform follow-on actions including information theft, making the lure set a targeted Korean social-engineering and downloader threat.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 01e7405ddd5545ffb4a57040acc4b6f… | 2023-07-20 | 2023-09-13 |
| HASH | f5e46e18facc6f8fde6658b96dcd379… | 2023-07-20 | 2023-09-13 |
| URL | https://atusay.lat/kxydo | 2023-07-20 | 2023-08-30 |
| DOMAIN | atusay.lat | 2023-07-20 | 2023-08-30 |
| URL | https://crilts.cfd/cdeeb | 2023-07-20 | 2023-08-25 |
| DOMAIN | crilts.cfd | 2023-07-20 | 2023-08-25 |
| HASH | fcfb0398eb0216332bb3ce25e5e353e… | 2023-07-20 | 2023-07-27 |
| HASH | eb21cf8e6f64340216e9c326fb58956… | 2023-07-20 | 2023-07-27 |
| URL | https://labimy.ink/rskme | 2023-07-20 | 2023-07-27 |
| URL | https://ppangz.mom/mjifi | 2023-07-20 | 2023-07-27 |
| DOMAIN | ppangz.mom | 2023-07-20 | 2023-07-27 |
| DOMAIN | labimy.ink | 2023-07-20 | 2023-07-27 |