CHM 파일로 유포되는 정보유출 악성코드
2023-07-21 • Ahnlab • Information leakage malware distributed as CHM files •
ASEC describes an information-stealing malware campaign delivered through CHM files that impersonated Korean financial firms and insurers around billing dates likely to make recipients trust the lures. The CHM execution chain used hh.exe to open the help file, decompiled content to C:\Users\Public\Libraries, ran Docs.jse with wscript, registered persistence, and launched command-line/PowerShell activity to retrieve alg.exe. EDR telemetry showed the downloaded stealer collecting PC, directory, and browser information, compressing stolen data under Public\Pictures, and transmitting it to an attacker-controlled server. The report provides hashes, detection names, and multiple download URLs associated with the CHM dropper and infostealer stages.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://tosals.ink/uEH5J.html | 2023-07-21 | 2023-08-30 |
| DOMAIN | tosals.ink | 2023-07-21 | 2023-08-30 |
| URL | https://atusay.lat/kxydo | 2023-07-20 | 2023-08-30 |
| DOMAIN | atusay.lat | 2023-07-20 | 2023-08-30 |
| URL | https://crilts.cfd/cdeeb | 2023-07-20 | 2023-08-25 |
| DOMAIN | crilts.cfd | 2023-07-20 | 2023-08-25 |
| HASH | 150e53a8c852ac5f23f47aceef452542 | 2023-07-21 | 2023-07-27 |
| URL | https://snexby.sbs/svbgt | 2023-07-21 | 2023-07-27 |
| URL | https://skrids.cfd/elzal | 2023-07-21 | 2023-07-27 |
| URL | https://tosals.ink/kxydo | 2023-07-21 | 2023-07-27 |
| URL | https://drilts.sbs/zcwq | 2023-07-21 | 2023-07-27 |
| URL | https://sklims.lat/sbjcw | 2023-07-21 | 2023-07-27 |
| URL | https://sutezy.mom/nmjnq | 2023-07-21 | 2023-07-27 |
| URL | https://akriqa.xyz/qcknq | 2023-07-21 | 2023-07-27 |
| URL | https://frotsy.lol/cvxxv | 2023-07-21 | 2023-07-27 |
| URL | https://snivox.lat/craig | 2023-07-21 | 2023-07-27 |
| DOMAIN | akriqa.xyz | 2023-07-21 | 2023-07-27 |
| DOMAIN | snexby.sbs | 2023-07-21 | 2023-07-27 |
| DOMAIN | sklims.lat | 2023-07-21 | 2023-07-27 |
| DOMAIN | sutezy.mom | 2023-07-21 | 2023-07-27 |
| DOMAIN | skrids.cfd | 2023-07-21 | 2023-07-27 |
| DOMAIN | frotsy.lol | 2023-07-21 | 2023-07-27 |
| DOMAIN | drilts.sbs | 2023-07-21 | 2023-07-27 |
| DOMAIN | snivox.lat | 2023-07-21 | 2023-07-27 |
| HASH | 0f27c6e760c2a530ee59d955c566f6da | 2023-07-20 | 2023-07-27 |
| HASH | 59a924bb5cb286420edebf8d30ee424b | 2023-07-20 | 2023-07-27 |
| HASH | bfe2a0504f7fb1326128763644c88d37 | 2023-07-20 | 2023-07-27 |
| HASH | aaeb059d62c448cbea4cf96f1bbf9efa | 2023-07-20 | 2023-07-27 |
| URL | https://labimy.ink/rskme | 2023-07-20 | 2023-07-27 |
| URL | https://ppangz.mom/mjifi | 2023-07-20 | 2023-07-27 |
| DOMAIN | ppangz.mom | 2023-07-20 | 2023-07-27 |
| DOMAIN | labimy.ink | 2023-07-20 | 2023-07-27 |