제안서로 위장을 하고 있는 북한 코니(Konni) 에서 만든 악성코드-제안서(2025.4.11)

2025-04-24 Sakai Malware Created by North Korean Konni Disguised as a Proposal - Proposal (2025.4.11)

https://wezard4u.tistory.com/429464

Thumbnail for 제안서로 위장을 하고 있는 북한 코니(Konni) 에서 만든 악성코드-제안서(2025.4.11)

The Korean analysis attributes a proposal-themed LNK sample to North Korea's Konni group and provides MD5, SHA-1, and SHA-256 hashes for the malware. The shortcut launches cmd.exe to find PowerShell, locate a specially sized .lnk carrier, XOR-decode embedded payloads, execute a decoded file, unpack a CAB archive into the Public Documents path, run start.vbs, and delete the LNK and CAB staging files. Follow-on batch scripts add persistence through HKCU\Software\Microsoft\Windows\CurrentVersion\Run, download a password-protected ZIP from ausbildungsbuddy.de, and execute additional content. The malware also enumerates the user's Downloads, Documents, and Desktop folders, collects system information, and uploads the resulting files to attacker-controlled PHP endpoints.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ystem.io 2023-09-26 2025-08-21
HASH 777b6a02f7a44582c40ddadb82e60ddb 2025-04-24 2025-05-19
URL https://ausbildungsbuddy.de/mod… 2025-04-23 2025-05-19
URL https://ausbildungsbuddy.de/mod… 2025-04-23 2025-05-19
DOMAIN ausbildungsbuddy.de 2025-04-23 2025-05-19
HASH 6af737ebc782825ebeb7dba389770a8… 2025-04-24 2025-04-24
HASH 401f5a93a9496262fc83ea4cf557e4e… 2025-04-24 2025-04-24

Related Actors

Related Reports

« Back