CHM 파일로 유포되는 정보유출 악성코드

2023-07-21 Ahnlab Information leakage malware distributed as CHM files

https://asec.ahnlab.com/ko/55462/

Thumbnail for CHM 파일로 유포되는 정보유출 악성코드

ASEC describes an information-stealing malware campaign delivered through CHM files that impersonated Korean financial firms and insurers around billing dates likely to make recipients trust the lures. The CHM execution chain used hh.exe to open the help file, decompiled content to C:\Users\Public\Libraries, ran Docs.jse with wscript, registered persistence, and launched command-line/PowerShell activity to retrieve alg.exe. EDR telemetry showed the downloaded stealer collecting PC, directory, and browser information, compressing stolen data under Public\Pictures, and transmitting it to an attacker-controlled server. The report provides hashes, detection names, and multiple download URLs associated with the CHM dropper and infostealer stages.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://tosals.ink/uEH5J.html 2023-07-21 2023-08-30
DOMAIN tosals.ink 2023-07-21 2023-08-30
URL https://atusay.lat/kxydo 2023-07-20 2023-08-30
DOMAIN atusay.lat 2023-07-20 2023-08-30
URL https://crilts.cfd/cdeeb 2023-07-20 2023-08-25
DOMAIN crilts.cfd 2023-07-20 2023-08-25
HASH 150e53a8c852ac5f23f47aceef452542 2023-07-21 2023-07-27
URL https://snexby.sbs/svbgt 2023-07-21 2023-07-27
URL https://skrids.cfd/elzal 2023-07-21 2023-07-27
URL https://tosals.ink/kxydo 2023-07-21 2023-07-27
URL https://drilts.sbs/zcwq 2023-07-21 2023-07-27
URL https://sklims.lat/sbjcw 2023-07-21 2023-07-27
URL https://sutezy.mom/nmjnq 2023-07-21 2023-07-27
URL https://akriqa.xyz/qcknq 2023-07-21 2023-07-27
URL https://frotsy.lol/cvxxv 2023-07-21 2023-07-27
URL https://snivox.lat/craig 2023-07-21 2023-07-27
DOMAIN akriqa.xyz 2023-07-21 2023-07-27
DOMAIN snexby.sbs 2023-07-21 2023-07-27
DOMAIN sklims.lat 2023-07-21 2023-07-27
DOMAIN sutezy.mom 2023-07-21 2023-07-27
DOMAIN skrids.cfd 2023-07-21 2023-07-27
DOMAIN frotsy.lol 2023-07-21 2023-07-27
DOMAIN drilts.sbs 2023-07-21 2023-07-27
DOMAIN snivox.lat 2023-07-21 2023-07-27
HASH 0f27c6e760c2a530ee59d955c566f6da 2023-07-20 2023-07-27
HASH 59a924bb5cb286420edebf8d30ee424b 2023-07-20 2023-07-27
HASH bfe2a0504f7fb1326128763644c88d37 2023-07-20 2023-07-27
HASH aaeb059d62c448cbea4cf96f1bbf9efa 2023-07-20 2023-07-27
URL https://labimy.ink/rskme 2023-07-20 2023-07-27
URL https://ppangz.mom/mjifi 2023-07-20 2023-07-27
DOMAIN ppangz.mom 2023-07-20 2023-07-27
DOMAIN labimy.ink 2023-07-20 2023-07-27

Related Reports

« Back