개인정보 유출 관련 내용으로 위장한 피싱 메일 유포 (Konni)

2023-12-06 Ahnlab Distribution of phishing emails disguised as content related to personal information leakage (Konni)

https://asec.ahnlab.com/ko/59625/

Thumbnail for 개인정보 유출 관련 내용으로 위장한 피싱 메일 유포 (Konni)

ASEC observed Konni phishing emails delivering a malicious EXE disguised as personal data leak material to individual users. Execution drops obfuscated JSE scripts, a PowerShell script, and a legitimate decoy DOC into ProgramData; Operator.jse creates a scheduled task that runs WindowsHotfixUpdate.jse every minute. The PowerShell component is designed to receive obfuscated C2 commands and execute them in XML form, with Lomd02.png handling deobfuscation, although ASEC could not observe final commands because the C2 was unavailable. ASEC lists Backdoor/JS.Konni, Backdoor/Win.Konni, Backdoor/PowerShell.Konni detections and a gjdow.atwebpages.com C2 URL among the indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b58eb8a3797d3a52aba30d91d207b688 2023-12-06 2024-09-05
DOMAIN gjdow.atwebpages.com 2023-12-06 2024-09-05
HASH a93474c3978609c8480b34299bf482b7 2023-12-06 2023-12-11
HASH 682b5a3c93e107511fdd2cdb8e50389a 2023-12-06 2023-12-11
HASH 78ea811850e01544ca961f181030b584 2023-12-06 2023-12-11
HASH d634cb7b45217ca4fd7eca5685a64f50 2023-12-06 2023-12-11
HASH d06d1c2ec1490710133dea445f33bd19 2023-12-06 2023-12-11

Related Actors

Related Reports

« Back