북한 해킹 단체 코니(Konni) 에서 만든 악성코드-2024년 귀속 연말정산 안내문_세한.docx(2025.2.28)
2025-03-07 • Sakai • Konni Malware Disguised as a 2024 Year-End Tax Settlement Guide •
A Konni-linked LNK sample masqueraded as a 2024 year-end tax settlement guide document and embedded heavily obfuscated PowerShell in the shortcut command line. The script searched for a PowerShell executable, extracted and XOR-decrypted payload data from the LNK, executed the recovered payload, created a CAB archive, expanded files into a public documents path, and deleted staging files. Follow-on batch scripts downloaded a ZIP from acschoolcatering.com, unpacked and ran additional content, collected file listings from Downloads, Documents, and Desktop along with system information, and uploaded the data to roofcolor.com over HTTP POST. The excerpt lists hashes for the LNK sample and shows infrastructure including acschoolcatering.com and roofcolor.com, making the activity useful for tracking Konni tradecraft around document-themed LNK delivery, payload staging, and host reconnaissance.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a2785ec65622217be80174b887b1eb06 | 2025-03-07 | 2025-03-28 |
| HASH | b81513f0f8d3db382bb8f931bf2b7a0… | 2025-03-07 | 2025-03-28 |
| URL | http://www.roofcolor.com/wp-inc… | 2025-03-07 | 2025-03-28 |
| DOMAIN | roofcolor.com | 2025-03-07 | 2025-03-28 |
| HASH | 5820e221437e87d6663adaddedb05bb… | 2025-03-07 | 2025-03-07 |
| URL | http://www.roofcolor.com/wp-inc… | 2025-03-07 | 2025-03-07 |
| URL | https://www.acschoolcatering.co… | 2025-03-07 | 2025-03-07 |