북한 해킹 단체 Konni(코니)에서 만든 악성코드-소명자료 목록(국세징수법 시행규칙)(2023.4.14)
2023-08-08 • Sakai • List of malware-explanation materials created by North Korean hacking group Konni (National Tax Collection Act Enforcement Rules) (April 14, 2023) •
The source analyzes a Konni-attributed ZIP-delivered LNK malware lure using Korean tax and explanatory-material document names. The malicious LNK was unusually large and contained an obfuscated PowerShell command that ran hidden, decoded hex-encoded script content, extracted embedded payload data from the shortcut, and wrote files under public user directories. The chain produced document decoys and launched a VBS script from a public documents/start path, while removing staging artifacts to reduce visibility. The article links Konni to North Korea-associated activity and provides MD5, SHA-1, and SHA-256 hashes for the LNK sample.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://naver.drive001.com/v2/r… | 2023-08-08 | 2023-11-24 |
| DOMAIN | naver.drive001.com | 2023-08-08 | 2023-11-24 |
| URL | http://centhosting.net/upload.p… | 2023-05-05 | 2023-11-24 |
| URL | http://centhosting.net/list.php… | 2023-05-05 | 2023-11-24 |
| DOMAIN | centhosting.net | 2023-05-05 | 2023-11-24 |
| HASH | b132c1ff68e000a70b3c085cfdd72feb | 2023-08-08 | 2023-08-08 |
| HASH | b79a681f10ff05f376080f74417cdc8… | 2023-08-08 | 2023-08-08 |
| HASH | 75726e20244a6f696578706e6745647… | 2023-08-08 | 2023-08-08 |
| HASH | 7042796e57456f293b246e444143526… | 2023-08-08 | 2023-08-08 |
| HASH | 746172742e766273273b2620246c4a6… | 2023-08-08 | 2023-08-08 |
| HASH | 60b06121a2952b2cd37c07cbe831e1d… | 2023-08-08 | 2023-08-08 |
| HASH | 4f555644454e66203d204765742d4c6f | 2023-08-08 | 2023-08-08 |
| DOMAIN | epos-c.biuzoyb.cn | 2023-08-08 | 2023-08-08 |