국내 금융 기업 및 보험사를 사칭한 CHM 악성코드
2023-07-20 • Ahnlab • CHM malware impersonating domestic financial companies and insurance companies •
ASEC describes CHM malware distributed in RAR archives while impersonating Korean financial firms and insurers with decoy help-window content about card limits, insurance withdrawals, and bank contracts. When opened, the CHM script decompiled files to C:\Users\Public\Libraries, executed Docs.jse with wscript, and used a Run-key entry for persistence. The script then launched PowerShell to download an additional payload as %tmp%\alg.exe from multiple attacker-controlled URLs, although the payload servers were unavailable during analysis. AhnLab classified the samples as Dropper/CHM.Generic and warned that the final payload could enable information theft or other follow-on activity depending on what was retrieved.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://atusay.lat/kxydo | 2023-07-20 | 2023-08-30 |
| DOMAIN | atusay.lat | 2023-07-20 | 2023-08-30 |
| URL | https://crilts.cfd/cdeeb | 2023-07-20 | 2023-08-25 |
| DOMAIN | crilts.cfd | 2023-07-20 | 2023-08-25 |
| HASH | 0f27c6e760c2a530ee59d955c566f6da | 2023-07-20 | 2023-07-27 |
| HASH | 59a924bb5cb286420edebf8d30ee424b | 2023-07-20 | 2023-07-27 |
| HASH | bfe2a0504f7fb1326128763644c88d37 | 2023-07-20 | 2023-07-27 |
| HASH | aaeb059d62c448cbea4cf96f1bbf9efa | 2023-07-20 | 2023-07-27 |
| URL | https://labimy.ink/rskme | 2023-07-20 | 2023-07-27 |
| URL | https://ppangz.mom/mjifi | 2023-07-20 | 2023-07-27 |
| DOMAIN | ppangz.mom | 2023-07-20 | 2023-07-27 |
| DOMAIN | labimy.ink | 2023-07-20 | 2023-07-27 |