비트코인 시세 급등에 따른 해킹 피해 주의보
2024-03-13 • Genians • Hacking damage warning due to rapid rise in Bitcoin price •
Genians analyzes a Konni APT campaign using Bitcoin market interest and virtual-asset exchange themes to deliver malware in South Korea. The attack distributes a ZIP containing a decoy PDF and a malicious LNK disguised as a DOCX personal-information consent form; the LNK runs obfuscated PowerShell, creates a replacement DOCX and UHCYbG.cab under public paths, then launches VBS and batch components. Follow-on scripts collect download, document, desktop, and system information, attempt exfiltration to stuckss.com, and download additional payloads from attacker-controlled infrastructure such as goosess.com. The source links the activity to earlier Konni campaigns through code similarity and LNK, VBS, and BAT tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | stuckss.com | 2024-03-11 | 2024-06-17 |
| DOMAIN | goosess.com | 2024-03-11 | 2024-06-17 |
| HASH | 655893b1641565f8ea04da4d74116b8a | 2024-03-11 | 2024-03-26 |
| HASH | a2c40c8b4aebee3f558ffb0f0e807852 | 2024-03-13 | 2024-03-13 |
| HASH | c8c9fef7678d9d3e3dedef57b328c080 | 2024-03-13 | 2024-03-13 |
| HASH | 3e16b90540bb6086c604d0353f5f9a7f | 2024-03-13 | 2024-03-13 |
| HASH | 23fbc0f35f33ec0abc100e0dd5e21033 | 2024-03-13 | 2024-03-13 |
| HASH | d6f4d4a85d7b8b940bf6155806d6f930 | 2024-03-13 | 2024-03-13 |
| HASH | d8047ac489bc55b1353904b986c53059 | 2024-03-13 | 2024-03-13 |
| HASH | 1af7148dc027753297e0f28770f16d4e | 2024-03-13 | 2024-03-13 |
| HASH | 396a9b9d9e1a0489b91f9e1ac5dc6411 | 2024-03-13 | 2024-03-13 |