제안서로 위장을 하고 있는 북한 코니(Konni) 에서 만든 악성코드-제안서(2025.4.11)
2025-04-24 • Sakai • Malware Created by North Korean Konni Disguised as a Proposal - Proposal (2025.4.11) •
The Korean analysis attributes a proposal-themed LNK sample to North Korea's Konni group and provides MD5, SHA-1, and SHA-256 hashes for the malware. The shortcut launches cmd.exe to find PowerShell, locate a specially sized .lnk carrier, XOR-decode embedded payloads, execute a decoded file, unpack a CAB archive into the Public Documents path, run start.vbs, and delete the LNK and CAB staging files. Follow-on batch scripts add persistence through HKCU\Software\Microsoft\Windows\CurrentVersion\Run, download a password-protected ZIP from ausbildungsbuddy.de, and execute additional content. The malware also enumerates the user's Downloads, Documents, and Desktop folders, collects system information, and uploads the resulting files to attacker-controlled PHP endpoints.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ystem.io | 2023-09-26 | 2025-08-21 |
| HASH | 777b6a02f7a44582c40ddadb82e60ddb | 2025-04-24 | 2025-05-19 |
| URL | https://ausbildungsbuddy.de/mod… | 2025-04-23 | 2025-05-19 |
| URL | https://ausbildungsbuddy.de/mod… | 2025-04-23 | 2025-05-19 |
| DOMAIN | ausbildungsbuddy.de | 2025-04-23 | 2025-05-19 |
| HASH | 6af737ebc782825ebeb7dba389770a8… | 2025-04-24 | 2025-04-24 |
| HASH | 401f5a93a9496262fc83ea4cf557e4e… | 2025-04-24 | 2025-04-24 |