부가가치세 신고 파일로 위장한 문서형 악성코드 분석 (Konni APT 캠페인)

2024-09-02 Sands Lab Document malware disguised as a value-added tax filing in a Konni APT campaign

https://blog.naver.com/PostView.naver?blogId=sandslab&logNo=223569075065

Thumbnail for 부가가치세 신고 파일로 위장한 문서형 악성코드 분석 (Konni APT 캠페인)

Sands Lab analyzed a Konni-linked campaign that used South Korea value-added tax filing themes to lure users into opening a malicious LNK file disguised as a HWP document. The LNK extracted an obfuscated PowerShell script, dropped a decoy document and Byimtb.cab under Public Documents, then used start.vbs and modular batch scripts to hide execution and maintain persistence through the Run registry key. The batch modules collected file listings from Desktop, Downloads, and Documents plus systeminfo output, then attempted to exfiltrate data to sibbss.com and fetch additional payloads from radionaranjalstereo.com. The report notes that syntax and TLS/certificate problems likely prevented some later-stage downloads, but the tooling, upload structure, bundled unzip.exe, and modular batch workflow match known Konni activity. The conclusion frames the activity as reconnaissance or initial access against public-sector finance personnel and says it closely resembles campaigns associated with North Korea's APT37.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 670892dc616431a25b6dfcf4d0223bd… 2024-09-02 2024-09-02
HASH 87e700c2707d58a18fbb9f0085b7817… 2024-09-02 2024-09-02
HASH 69f1458e75a5781335f2fb0d751a083… 2024-09-02 2024-09-02
HASH 8f164ca160b458af126d70f356ad47b… 2024-09-02 2024-09-02
HASH e7a9da4f70299216d368b366a4544ff… 2024-09-02 2024-09-02
HASH 6d901221cb5162c190cce720726889c… 2024-09-02 2024-09-02
HASH c0b1ee982cc6a2b805ec3a2fa8a59fd… 2024-09-02 2024-09-02
HASH ef6bcf1657099879e990641d4c23d7f… 2024-09-02 2024-09-02
HASH f212e1414092d09ac103be3f2c48cb2… 2024-09-02 2024-09-02
HASH 8d9b5190aace52a1db1ac73a65ee999… 2024-09-02 2024-09-02
HASH df26abadb207e3e264f1910c5119ce3… 2024-09-02 2024-09-02
HASH d81713d1d8d462db8b6468b0a813e8a… 2024-09-02 2024-09-02
URL http://sibbss.com/post.php 2024-09-02 2024-09-02
URL http://sibbss.com/list.php 2024-09-02 2024-09-02
IPv4 213.158.94.166 2024-09-02 2024-09-02
IPv4 176.97.64.174 2024-09-02 2024-09-02
URL https://radionaranjalstereo.com… 2024-08-22 2024-09-02
DOMAIN radionaranjalstereo.com 2024-08-22 2024-09-02
DOMAIN sibbss.com 2024-08-22 2024-09-02
HASH 9762d5c00cdc58e774676ab868a5928… 2023-11-24 2024-09-02

Related Actors

Related Reports

« Back