북한 해킹 단체 Konni(코니) 암호화폐 거래소 빗썸(Bithumb) 정보 업데이트 요청으르로 위장한 악성코드-금융당국 요청에 따른 프로젝트 정보 확인 요청의 건.zip(2024.7.23)
2024-07-25 • Sakai • Malware from the North Korean Hacking Group Konni Disguised as a Request to Update Information for Cryptocurrency Exchange Bithumb - Request to Confirm Project Information Under Financial Authority Requirements.zip (2024.7.23) •
A Konni-themed intrusion used a ZIP lure impersonating a Bithumb cryptocurrency-exchange information update request tied to financial-authority project reporting. The archive contained a decoy PDF and a large Windows shortcut disguised as an Excel file, with the LNK embedding obfuscated PowerShell that extracts XOR-encoded payload data into Public Documents. The execution chain creates and runs VBS and batch scripts, collects file listings from Downloads, Documents, and Desktop plus system information, and uploads the results to hxxp://shutss(.)com/upload(.)php. The source links Konni to North Korean activity including Thallium/APT37 and possible Kimsuky overlap, while noting this specific lure appears aimed at cryptocurrency-related targets and lists infrastructure including shutss(.)com and thevintagegarage(.)com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | thevintagegarage.com | 2024-07-25 | 2025-05-19 |
| HASH | 65bc642b1c454d314ad71c5f4a2348f… | 2024-07-25 | 2024-07-25 |
| HASH | 6155d592e9083937ae5dadb304a69053 | 2024-07-25 | 2024-07-25 |
| HASH | 3a2d628db6cd2a526ee908d3a4763b1… | 2024-07-25 | 2024-07-25 |
| HASH | 0e491c00e5c4be460cb4632d96e4963… | 2024-07-25 | 2024-07-25 |
| HASH | d3c78ad4977d486defeb72f888e3f0c… | 2024-07-25 | 2024-07-25 |
| URL | https://thevintagegarage.com | 2024-07-25 | 2024-07-25 |
| URL | http://shutss.com/list.php?6385… | 2024-07-25 | 2024-07-25 |
| IPv4 | 35.245.79.218 | 2024-07-25 | 2024-07-25 |
| HASH | e3eeeebb117b7c3128d87b6e027bd85d | 2024-07-25 | 2024-07-25 |
| URL | http://shutss.com/upload.php | 2024-07-25 | 2024-07-25 |
| DOMAIN | shutss.com | 2024-07-25 | 2024-07-25 |