CHM Impersonates Korean Financial Institutes and Insurance Companies

2023-07-27 Ahnlab

https://asec.ahnlab.com/en/55569/

Thumbnail for CHM Impersonates Korean Financial Institutes and Insurance Companies

AhnLab ASEC reported CHM malware distributed in RAR archives that impersonated Korean financial institutions and insurance companies with themes such as credit-card limits, insurance-fee withdrawal results, and banking contracts. When opened, the CHM decompiled content under C:\Users\Public\Libraries and executed an encoded Docs.jse script through wscript. The script added persistence through the Run key and used PowerShell to download an additional payload as %tmp%\alg.exe from actor-controlled URLs such as ppangz[.]mom and crilts[.]cfd. ASEC warned that the downloaded malware could perform follow-on actions including information theft, making the lure set a targeted Korean social-engineering and downloader threat.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://atusay.lat/kxydo 2023-07-20 2023-08-30
DOMAIN atusay.lat 2023-07-20 2023-08-30
URL https://crilts.cfd/cdeeb 2023-07-20 2023-08-25
DOMAIN crilts.cfd 2023-07-20 2023-08-25
HASH 0f27c6e760c2a530ee59d955c566f6da 2023-07-20 2023-07-27
HASH 59a924bb5cb286420edebf8d30ee424b 2023-07-20 2023-07-27
HASH bfe2a0504f7fb1326128763644c88d37 2023-07-20 2023-07-27
HASH aaeb059d62c448cbea4cf96f1bbf9efa 2023-07-20 2023-07-27
URL https://labimy.ink/rskme 2023-07-20 2023-07-27
URL https://ppangz.mom/mjifi 2023-07-20 2023-07-27
DOMAIN ppangz.mom 2023-07-20 2023-07-27
DOMAIN labimy.ink 2023-07-20 2023-07-27

Related Actors

Related Reports

« Back