금융기관을 사칭하는 피싱 메일 주의

2023-08-01 Hauri Beware of phishing emails impersonating financial institutions

https://hauri.co.kr/security/issue_view.html?intSeq=421&page=1&article_num=332

Thumbnail for 금융기관을 사칭하는 피싱 메일 주의

Hauri warns that phishing emails impersonating financial institutions were distributing CHM malware using finance-themed attachments such as product contracts, automatic insurance-payment notices, card-limit changes, and tax invoices. After extraction, the CHM package contains an HTML file and encoded Docs.jse; embedded script decodes the CHM, hides the JSE in a public library path, and launches it with wscript. The malware registers the JSE for autorun persistence and uses PowerShell to reach a malicious site and download an additional payload. The source identifies the download command targeting drimby.top/wndfi and detects the threat as HTML.S.CHMPhishing.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://drimby.top/wndfi 2023-08-01 2023-08-21
DOMAIN drimby.top 2023-08-01 2023-08-21

Related Reports

« Back