Attachment: Archive with embedded CHM file
Recursively scans files and archives to detect embedded CHM (Microsoft Compiled HTML Help) files.
According to CERT-UA, on March 7, 2022, phishing attacks targeted state organizations of Ukraine
using Zip files with embedded CHM documents, which themselves contained malicious VBScript inside a .htm file.
The activity is associated with UNC1151, according to CERT-UA.
type.inbound and any(attachments, .file_extension in~ $file_extensions_common_archives and any(file.explode(.), .file_extension =~ "chm") )
Test against your own EMLs or sample data.
Get Started. Today.
Managed or self-managed. No MX changes.