Analysis of *.chm malware
2024-04-05 • Plainbit •
Plainbit analyzed a paymentconfirmation.chm sample that used a normal-looking help window to hide script execution through hh.exe, cscript, VBS, batch files, and PowerShell. The CHM unpacked files under C:\Users\Public\Libraries, registered emlmanager.vbs as a scheduled task, and used batch scripts to collect systeminfo, tasklist output, and Desktop and Downloads directory listings. Collected data was compressed, Base64-encoded, and uploaded to niscarea.com through in.php, while out.php appeared to return an additional ZIP payload for follow-on execution. The report maps the activity to phishing, system binary proxy execution, script execution, discovery, staging, C2 transfer, and exfiltration techniques, with hashes for the CHM and related scripts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://niscarea.com | 2023-11-28 | 2024-12-27 |
| DOMAIN | niscarea.com | 2023-11-28 | 2024-12-27 |
| HASH | e585226bcbec086b268528489103a6d5 | 2024-04-05 | 2024-04-05 |
| HASH | be0a4914e662724b7e924f35dce751c5 | 2024-04-05 | 2024-04-05 |
| HASH | 24f6323110ac1e57eee2b2dc74886460 | 2024-04-05 | 2024-04-05 |
| HASH | 0a8ce62791c48d70f5d31b290cfbeb32 | 2024-04-05 | 2024-04-05 |
| HASH | 859700ae5a1a3302dc17063a6c9ee61b | 2024-04-05 | 2024-04-05 |
| HASH | b72cb01d8650a0a98bc8e62a86127ca0 | 2024-04-05 | 2024-04-05 |
| HASH | f070a3bd5efcced27baeae32ad25de36 | 2024-04-05 | 2024-04-05 |
| HASH | d8eb9c484c9d5e1dd3c60cdd41323433 | 2024-04-05 | 2024-04-05 |
| HASH | 07f1c2d7f5877dea5bd8225533b3d19e | 2024-04-05 | 2024-04-05 |
| URL | https://niscarea.com/out.php?cn= | 2024-04-05 | 2024-04-05 |
| URL | https://niscarea.com/in.php?cn= | 2024-04-05 | 2024-04-05 |
| URL | https://niscarea.com/?cn= | 2024-04-05 | 2024-04-05 |
| HASH | 2548d0e05c47c506cf9fd668dace5497 | 2024-01-17 | 2024-04-05 |
| HASH | fd47c8418d9f8ed39f2f746042c982a… | 2024-01-17 | 2024-04-05 |
| HASH | 8ac21a35158ba9ebf80493bdb8cf8eb… | 2024-01-17 | 2024-04-05 |
| URL | https://niscarea.com/ | 2024-01-17 | 2024-04-05 |