북한 해킹 단체 코니(Konni) 에서 만든 악성코드-2024년 귀속 연말정산 안내문_세한.docx(2025.2.28)

2025-03-07 Sakai Konni Malware Disguised as a 2024 Year-End Tax Settlement Guide

https://wezard4u.tistory.com/429425

Thumbnail for 북한 해킹 단체 코니(Konni) 에서 만든 악성코드-2024년 귀속 연말정산 안내문_세한.docx(2025.2.28)

A Konni-linked LNK sample masqueraded as a 2024 year-end tax settlement guide document and embedded heavily obfuscated PowerShell in the shortcut command line. The script searched for a PowerShell executable, extracted and XOR-decrypted payload data from the LNK, executed the recovered payload, created a CAB archive, expanded files into a public documents path, and deleted staging files. Follow-on batch scripts downloaded a ZIP from acschoolcatering.com, unpacked and ran additional content, collected file listings from Downloads, Documents, and Desktop along with system information, and uploaded the data to roofcolor.com over HTTP POST. The excerpt lists hashes for the LNK sample and shows infrastructure including acschoolcatering.com and roofcolor.com, making the activity useful for tracking Konni tradecraft around document-themed LNK delivery, payload staging, and host reconnaissance.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a2785ec65622217be80174b887b1eb06 2025-03-07 2025-03-28
HASH b81513f0f8d3db382bb8f931bf2b7a0… 2025-03-07 2025-03-28
URL http://www.roofcolor.com/wp-inc… 2025-03-07 2025-03-28
DOMAIN roofcolor.com 2025-03-07 2025-03-28
HASH 5820e221437e87d6663adaddedb05bb… 2025-03-07 2025-03-07
URL http://www.roofcolor.com/wp-inc… 2025-03-07 2025-03-07
URL https://www.acschoolcatering.co… 2025-03-07 2025-03-07

Related Actors

Related Reports

« Back