북한 해킹 단체 Konni(코니)에서 만든 파워포인트 악성코드(2023.5.24)

2023-05-31 Sakai PowerPoint malware created by North Korean hacking group Konni (2023.5.24)

https://wezard4u.tistory.com/6456

Thumbnail for 북한 해킹 단체 Konni(코니)에서 만든 파워포인트 악성코드(2023.5.24)

The Korean write-up analyzes a Konni-linked PowerPoint sample attributed by the source to a North Korean hacking group associated with Thallium/APT37 and possibly Kimsuky. The lure masquerades as a PPTX file but contains VBA that displays a fake PowerPoint version error, writes a Base64 blob to disk, decodes it with Certutil into %LOCALAPPDATA%\Microsoft\Office\oup.vbs, and runs it after a delay. The decoded script creates a scheduled task named “Office Updatev2.2” every five minutes and launches PowerShell with execution-policy bypass to download Base64 content from gg1593.c1.biz/dn.php using the host name and OS version as parameters, then loads and invokes the returned .NET assembly. The source lists representative hashes for the PPTX sample, including SHA-256 b97e12807dcde2a8fd53d7f8e74336442d0cf8dbed19c0a44fcef359160bdd77.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN gg1593.c1.biz 2022-08-26 2024-09-05
HASH 3a3ce0a1794b548682167da692052dc2 2023-05-31 2023-05-31
HASH b97e12807dcde2a8fd53d7f8e743364… 2023-05-31 2023-05-31
HASH 061e17f3b2fd4a4dce1bf4f8a311982… 2023-05-31 2023-05-31
HASH 9f94236a481b957890cc7f7a85dc905… 2023-05-31 2023-05-31
URL http://gg1593.c1.biz/dn.php?nam… 2023-05-31 2023-05-31
URL http://gg1593.c1.biz/dn.php 2022-08-26 2023-05-31

Related Actors

Related Reports

« Back