금융기관을 사칭하는 피싱 메일 주의
2023-08-01 • Hauri • Beware of phishing emails impersonating financial institutions •
https://hauri.co.kr/security/issue_view.html?intSeq=421&page=1&article_num=332
Hauri warns that phishing emails impersonating financial institutions were distributing CHM malware using finance-themed attachments such as product contracts, automatic insurance-payment notices, card-limit changes, and tax invoices. After extraction, the CHM package contains an HTML file and encoded Docs.jse; embedded script decodes the CHM, hides the JSE in a public library path, and launches it with wscript. The malware registers the JSE for autorun persistence and uses PowerShell to reach a malicious site and download an additional payload. The source identifies the download command targeting drimby.top/wndfi and detects the threat as HTML.S.CHMPhishing.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://drimby.top/wndfi | 2023-08-01 | 2023-08-21 |
| DOMAIN | drimby.top | 2023-08-01 | 2023-08-21 |