부가가치세 신고 파일로 위장한 문서형 악성코드 분석 (Konni APT 캠페인)
2024-09-02 • Sands Lab • Document malware disguised as a value-added tax filing in a Konni APT campaign •
https://blog.naver.com/PostView.naver?blogId=sandslab&logNo=223569075065
Sands Lab analyzed a Konni-linked campaign that used South Korea value-added tax filing themes to lure users into opening a malicious LNK file disguised as a HWP document. The LNK extracted an obfuscated PowerShell script, dropped a decoy document and Byimtb.cab under Public Documents, then used start.vbs and modular batch scripts to hide execution and maintain persistence through the Run registry key. The batch modules collected file listings from Desktop, Downloads, and Documents plus systeminfo output, then attempted to exfiltrate data to sibbss.com and fetch additional payloads from radionaranjalstereo.com. The report notes that syntax and TLS/certificate problems likely prevented some later-stage downloads, but the tooling, upload structure, bundled unzip.exe, and modular batch workflow match known Konni activity. The conclusion frames the activity as reconnaissance or initial access against public-sector finance personnel and says it closely resembles campaigns associated with North Korea's APT37.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 670892dc616431a25b6dfcf4d0223bd… | 2024-09-02 | 2024-09-02 |
| HASH | 87e700c2707d58a18fbb9f0085b7817… | 2024-09-02 | 2024-09-02 |
| HASH | 69f1458e75a5781335f2fb0d751a083… | 2024-09-02 | 2024-09-02 |
| HASH | 8f164ca160b458af126d70f356ad47b… | 2024-09-02 | 2024-09-02 |
| HASH | e7a9da4f70299216d368b366a4544ff… | 2024-09-02 | 2024-09-02 |
| HASH | 6d901221cb5162c190cce720726889c… | 2024-09-02 | 2024-09-02 |
| HASH | c0b1ee982cc6a2b805ec3a2fa8a59fd… | 2024-09-02 | 2024-09-02 |
| HASH | ef6bcf1657099879e990641d4c23d7f… | 2024-09-02 | 2024-09-02 |
| HASH | f212e1414092d09ac103be3f2c48cb2… | 2024-09-02 | 2024-09-02 |
| HASH | 8d9b5190aace52a1db1ac73a65ee999… | 2024-09-02 | 2024-09-02 |
| HASH | df26abadb207e3e264f1910c5119ce3… | 2024-09-02 | 2024-09-02 |
| HASH | d81713d1d8d462db8b6468b0a813e8a… | 2024-09-02 | 2024-09-02 |
| URL | http://sibbss.com/post.php | 2024-09-02 | 2024-09-02 |
| URL | http://sibbss.com/list.php | 2024-09-02 | 2024-09-02 |
| IPv4 | 213.158.94.166 | 2024-09-02 | 2024-09-02 |
| IPv4 | 176.97.64.174 | 2024-09-02 | 2024-09-02 |
| URL | https://radionaranjalstereo.com… | 2024-08-22 | 2024-09-02 |
| DOMAIN | radionaranjalstereo.com | 2024-08-22 | 2024-09-02 |
| DOMAIN | sibbss.com | 2024-08-22 | 2024-09-02 |
| HASH | 9762d5c00cdc58e774676ab868a5928… | 2023-11-24 | 2024-09-02 |