국내 금융 기업 및 보험사를 사칭한 CHM 악성코드

2023-07-20 Ahnlab CHM malware impersonating domestic financial companies and insurance companies

https://asec.ahnlab.com/ko/55351/

Thumbnail for 국내 금융 기업 및 보험사를 사칭한 CHM 악성코드

ASEC describes CHM malware distributed in RAR archives while impersonating Korean financial firms and insurers with decoy help-window content about card limits, insurance withdrawals, and bank contracts. When opened, the CHM script decompiled files to C:\Users\Public\Libraries, executed Docs.jse with wscript, and used a Run-key entry for persistence. The script then launched PowerShell to download an additional payload as %tmp%\alg.exe from multiple attacker-controlled URLs, although the payload servers were unavailable during analysis. AhnLab classified the samples as Dropper/CHM.Generic and warned that the final payload could enable information theft or other follow-on activity depending on what was retrieved.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://atusay.lat/kxydo 2023-07-20 2023-08-30
DOMAIN atusay.lat 2023-07-20 2023-08-30
URL https://crilts.cfd/cdeeb 2023-07-20 2023-08-25
DOMAIN crilts.cfd 2023-07-20 2023-08-25
HASH 0f27c6e760c2a530ee59d955c566f6da 2023-07-20 2023-07-27
HASH 59a924bb5cb286420edebf8d30ee424b 2023-07-20 2023-07-27
HASH bfe2a0504f7fb1326128763644c88d37 2023-07-20 2023-07-27
HASH aaeb059d62c448cbea4cf96f1bbf9efa 2023-07-20 2023-07-27
URL https://labimy.ink/rskme 2023-07-20 2023-07-27
URL https://ppangz.mom/mjifi 2023-07-20 2023-07-27
DOMAIN ppangz.mom 2023-07-20 2023-07-27
DOMAIN labimy.ink 2023-07-20 2023-07-27

Related Actors

Related Reports

« Back