북한 해킹 단체 Konni(코니)에서 만든 파워포인트 악성코드(2023.5.24)
2023-05-31 • Sakai • PowerPoint malware created by North Korean hacking group Konni (2023.5.24) •
The Korean write-up analyzes a Konni-linked PowerPoint sample attributed by the source to a North Korean hacking group associated with Thallium/APT37 and possibly Kimsuky. The lure masquerades as a PPTX file but contains VBA that displays a fake PowerPoint version error, writes a Base64 blob to disk, decodes it with Certutil into %LOCALAPPDATA%\Microsoft\Office\oup.vbs, and runs it after a delay. The decoded script creates a scheduled task named “Office Updatev2.2” every five minutes and launches PowerShell with execution-policy bypass to download Base64 content from gg1593.c1.biz/dn.php using the host name and OS version as parameters, then loads and invokes the returned .NET assembly. The source lists representative hashes for the PPTX sample, including SHA-256 b97e12807dcde2a8fd53d7f8e74336442d0cf8dbed19c0a44fcef359160bdd77.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | gg1593.c1.biz | 2022-08-26 | 2024-09-05 |
| HASH | 3a3ce0a1794b548682167da692052dc2 | 2023-05-31 | 2023-05-31 |
| HASH | b97e12807dcde2a8fd53d7f8e743364… | 2023-05-31 | 2023-05-31 |
| HASH | 061e17f3b2fd4a4dce1bf4f8a311982… | 2023-05-31 | 2023-05-31 |
| HASH | 9f94236a481b957890cc7f7a85dc905… | 2023-05-31 | 2023-05-31 |
| URL | http://gg1593.c1.biz/dn.php?nam… | 2023-05-31 | 2023-05-31 |
| URL | http://gg1593.c1.biz/dn.php | 2022-08-26 | 2023-05-31 |