CHM Impersonates Korean Financial Institutes and Insurance Companies
2023-07-27 • Ahnlab •
AhnLab ASEC reported CHM malware distributed in RAR archives that impersonated Korean financial institutions and insurance companies with themes such as credit-card limits, insurance-fee withdrawal results, and banking contracts. When opened, the CHM decompiled content under C:\Users\Public\Libraries and executed an encoded Docs.jse script through wscript. The script added persistence through the Run key and used PowerShell to download an additional payload as %tmp%\alg.exe from actor-controlled URLs such as ppangz[.]mom and crilts[.]cfd. ASEC warned that the downloaded malware could perform follow-on actions including information theft, making the lure set a targeted Korean social-engineering and downloader threat.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://atusay.lat/kxydo | 2023-07-20 | 2023-08-30 |
| DOMAIN | atusay.lat | 2023-07-20 | 2023-08-30 |
| URL | https://crilts.cfd/cdeeb | 2023-07-20 | 2023-08-25 |
| DOMAIN | crilts.cfd | 2023-07-20 | 2023-08-25 |
| HASH | 0f27c6e760c2a530ee59d955c566f6da | 2023-07-20 | 2023-07-27 |
| HASH | 59a924bb5cb286420edebf8d30ee424b | 2023-07-20 | 2023-07-27 |
| HASH | bfe2a0504f7fb1326128763644c88d37 | 2023-07-20 | 2023-07-27 |
| HASH | aaeb059d62c448cbea4cf96f1bbf9efa | 2023-07-20 | 2023-07-27 |
| URL | https://labimy.ink/rskme | 2023-07-20 | 2023-07-27 |
| URL | https://ppangz.mom/mjifi | 2023-07-20 | 2023-07-27 |
| DOMAIN | ppangz.mom | 2023-07-20 | 2023-07-27 |
| DOMAIN | labimy.ink | 2023-07-20 | 2023-07-27 |