주적 북한 해킹 단체 코니(Konni)에서 제작한 악성코드-자금출처명세서.lnk(2025.5.28)
2025-07-21 • Sakai • Malware Created by North Korean Hostile Hacking Group Konni - Statement of Source of Funds.lnk (2025.5.28) •
The source analyzes a Konni-attributed LNK malware sample disguised as a Hangul document named like a funds source statement. Its embedded PowerShell searches for a specifically sized .lnk file, extracts XOR-decoded payload data from offsets in that file, writes a CAB file under the Public documents path, expands it, and launches a VBS script. Follow-on batch scripts enumerate the user's Downloads, Documents, Desktop, and system information into text files for collection. The stealer logic encrypts local files with an RC4 implementation using a time-derived key, Base64-encodes the result, and POSTs it with a browser-like user agent. The exfiltration endpoint is hxxps://24hrkpop(.)com/wp-includes/js/src/lib/upload(.)php, and the source says the Korean K-pop website was compromised to support malware distribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ba708acd2ea044fd8076dfd1bb540e77 | 2025-07-21 | 2025-07-21 |
| HASH | 066ef37379b12dcd9e1524b936d65c0… | 2025-07-21 | 2025-07-21 |
| HASH | d5b59f06c2505cb28d1e7e52138b40e… | 2025-07-21 | 2025-07-21 |
| URL | https://24hrkpop.com/wp-include… | 2025-07-21 | 2025-07-21 |
| DOMAIN | 24hrkpop.com | 2025-07-21 | 2025-07-21 |