• Home
  • Forums
  • Chat
  • Categories
    • News
    • Tech
    • Gaming
    • Anime

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

AMD Ryzen 7000 and Socket AM5 alleged BIOS issues pushed availability date back

August 17, 2022

Ex-footballer called ‘team meetings’ with family over tablespoons being loaded incorrectly in dishwasher

August 17, 2022

Midterm election disinformation counterplans for Meta and TikTok

August 17, 2022
Facebook Twitter Instagram
Visit the Oasis
OasisNews
Facebook Twitter Instagram YouTube
  • Home
  • Forums
  • Chat
  • Categories
    • News
    • Tech
    • Gaming
    • Anime
OasisNews
Home»tech»AgentTesla Being Distributed Through Windows Help File (*.chm)
tech

AgentTesla Being Distributed Through Windows Help File (*.chm)

adminBy adminJune 2, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


The ASEC analysis team recently discovered AgentTesla being distributed with a new method. Previously, AgentTesla discussed in multiple ASEC blog posts was distributed by the malicious VBA macro inside PowerPoint files (*.ppt). However, the new method uses Windows Help files (*.chm) to run powershell commands.

The malicious CHM files are distributed as compressed files attached to phishing emails imitating emails sent from DHL, a transport company. As phishing emails disguised as other topics are also being distributed, users need to take caution.

Figure 1. DHL phishing email

Decompressing the attachment shows a malicious CHM file. When the file is run, it creates a normal Help window to make it difficult for users to realize malicious behaviors.

Figure 2. Normal Help window

However, the malicious script included in the internal HTML will perform malicious behaviors. Figures 3 and 4 show the obfuscated HTML including a malicious script, while Figures 5 and 6 show the unobfuscated code. You can see that the unobfuscated code uses a method that is similar to the one applied by malicious CHM files that have been introduced in the blog since March. The code includes a malicious command in a certain id property range and uses the Click() function to automatically run the command.

Figure 3. Obfuscated HTML type 1
Figure 4. Obfuscated HTML type 2
Figure 5. Unobfuscated HTML Type 1
Figure 6. Unobfuscated HTML Type 2

The command run from the script is a powershell type, which accesses certain URLs to download and run additional malicious data. Below is the list of malicious URLs discovered so far. Note that they all use the JPG extension.

  • Download URLs
    hxxp://pacurariu[.]com/F37.jpg
    hxxp://pk-consult[.]hr/N2.jpg
    hxxp://exipnikouzina[.]gr/S15.jpg

The data downloaded from the URLs are additional powershell commands. The distribution method discussed previously downloads and runs malicious data through the mshta process when the malicious VBA macro inside the PowerPoint file is run. The data downloaded from the previous method was also powershell commands. The malware type and the execution method were similar as well. Yet the process of downloading data was changed from using the malicious VBA macro inside the PowerPoint file to using the malicious powershell command within the Windows help file.

The downloaded data performs a feature that is identical to the previous method: loading a malicious .NET executable. There are two binaries in total. The first one is AgentTesla which performs malicious behaviors, and the second is Loader which injects the malware into a normal process. They are run after being decompressed by gzip. The Loader decoded in the script runs the Black method of the toooyou class and includes the name of the normal process that will be targeted for injection and compressed AgentTesla binary as execution arguments.

Figure 7. Downloaded malicious powershell command

The following image shows the Black method that is executed. It decompresses AgentTesla and injects it into the RegAsm.exe process. The process allows the info-leaking malware AgentTesla to operate in a fileless form.

Figure 8. Code inside Loader

AgentTesla is a malware type that is ranked top 3 in AhnLab’s weekly malware statistics. It continues to show intricate changes among the malware types using PowerPoint for distribution. As malware types exploiting Windows Help files (*.chm) are on the rise recently, users need to take caution. They should refrain from running files with unknown sources.

AhnLab’s anti-malware product, V3, detects and blocks the malware using the alias below.

[File Detection]
Trojan/CHM.Agent (2022.05.16.01)
Trojan/CHM.Agent (2022.05.24.00)
Infostealer/Win.AgentTesla.R420346 (2021.05.12.04)

[IOC]
91dbec3653b27c394719fcf5341fe460
4e5ef8e38b17fdf30961f28d4b5e2e23
5d0fc901682170421ebdd5c1ce047c5e
156cbb249d592230bea8fadead028b6b
hxxp://pacurariu[.]com/F37.jpg
hxxp://pk-consult[.]hr/N2.jpg
hxxp://exipnikouzina[.]gr/S15.jpg

Subscribe to AhnLab’s next-generation threat intelligence platform ‘AhnLab TIP’ to check related IOC and detailed analysis information.



Source link

AgentTesla chm Distributed File Windows
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleWhat Really Is Trooping the Colour? History, Significance and Traditions
Next Article Terra’s new luna coin sees wild price fluctuations
admin
admin
  • Website

Related Posts

AMD Ryzen 7000 and Socket AM5 alleged BIOS issues pushed availability date back

August 17, 2022

Midterm election disinformation counterplans for Meta and TikTok

August 17, 2022

Beats Fit Pro in Kim Kardashian Colors Sold Out in US and Canada at Apple

August 17, 2022

Apple’s Mob Move | Coder Radio 479

August 17, 2022

Classic DOOM Fans Will Love This DOOM Voxel Mod; Available for Download Now

August 17, 2022

RADV Radeon Vulkan Driver Begins Landing Graphics Pipeline Library Support

August 17, 2022
0 0 votes
Article Rating
Subscribe
Login
Notify of
guest
guest
0 Comments
Inline Feedbacks
View all comments
Demo
Our Picks

Soneva’s Luxury Resorts Now Accept Crypto Payments – Featured Bitcoin News

August 17, 2022

‘Big Short’ Investor Michael Burry Dumps All Stocks but One After Predicting Market Crash – Featured Bitcoin News

August 17, 2022

Peter Schiff to Liquidate Euro Pacific Bank in Settlement With Puerto Rican Regulator – Featured Bitcoin News

August 14, 2022

Billionaire Mark Cuban Sued for Allegedly Promoting a Massive Crypto ‘Ponzi Scheme’ – Featured Bitcoin News

August 14, 2022
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
tech

AMD Ryzen 7000 and Socket AM5 alleged BIOS issues pushed availability date back

By adminAugust 17, 2022

At the Computex 2022 event in May, AMD revealed more details on its upcoming Zen…

Ex-footballer called ‘team meetings’ with family over tablespoons being loaded incorrectly in dishwasher

August 17, 2022

Midterm election disinformation counterplans for Meta and TikTok

August 17, 2022

Beats Fit Pro in Kim Kardashian Colors Sold Out in US and Canada at Apple

August 17, 2022

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

Top Posts
Advertisement
Demo
Latest Posts
Our Picks

Samsung Galaxy S22 series picks up the August 2022 security update in the US

August 14, 2022

Best Buy's anniversary sale is here: Our top deal picks

August 12, 2022

FTX.US President Brett Harrison Says Crypto Winter Fading Away As Institutional Demand Picks Up

August 10, 2022

Amazon picks up Roomba vacuum maker iRobot for $1.7 billion

August 7, 2022
Blog Posts

TenSura Anime Film Unveils 3 New Cast Members! | Anime News

August 17, 2022

Shangri-La Frontier Gets Anime and Game! | Anime News

August 17, 2022

Welcome to Demon School! Iruma-kun S3 Reveals Premiere Date! | Anime News

August 16, 2022

SK8 The Infinity confirmed the production of a second season and a new OVA

August 15, 2022

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

About Us
About Us

Weboasis is the number one home page for your browser on all of the internet. Providing you with links, places to communicate, and news, all in one little OASIS.

Facebook Twitter Instagram Pinterest
  • Home
  • Forums
  • Chat
  • Categories
    • News
    • Tech
    • Gaming
    • Anime
© 2022 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.

wpDiscuz