개인정보 유출 관련 내용으로 위장한 피싱 메일 유포 (Konni)
2023-12-06 • Ahnlab • Distribution of phishing emails disguised as content related to personal information leakage (Konni) •
ASEC observed Konni phishing emails delivering a malicious EXE disguised as personal data leak material to individual users. Execution drops obfuscated JSE scripts, a PowerShell script, and a legitimate decoy DOC into ProgramData; Operator.jse creates a scheduled task that runs WindowsHotfixUpdate.jse every minute. The PowerShell component is designed to receive obfuscated C2 commands and execute them in XML form, with Lomd02.png handling deobfuscation, although ASEC could not observe final commands because the C2 was unavailable. ASEC lists Backdoor/JS.Konni, Backdoor/Win.Konni, Backdoor/PowerShell.Konni detections and a gjdow.atwebpages.com C2 URL among the indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b58eb8a3797d3a52aba30d91d207b688 | 2023-12-06 | 2024-09-05 |
| DOMAIN | gjdow.atwebpages.com | 2023-12-06 | 2024-09-05 |
| HASH | a93474c3978609c8480b34299bf482b7 | 2023-12-06 | 2023-12-11 |
| HASH | 682b5a3c93e107511fdd2cdb8e50389a | 2023-12-06 | 2023-12-11 |
| HASH | 78ea811850e01544ca961f181030b584 | 2023-12-06 | 2023-12-11 |
| HASH | d634cb7b45217ca4fd7eca5685a64f50 | 2023-12-06 | 2023-12-11 |
| HASH | d06d1c2ec1490710133dea445f33bd19 | 2023-12-06 | 2023-12-11 |