코니(Konni) APT 조직, 러시아 문서로 위장한 공격 등장
2019-08-19 • ESTSecurity • Konni APT organization launches attack disguised as Russian document •
ESTsecurity analyzed a Konni-series malicious Word document using a Russian filename about the Korean Peninsula and U.S.–DPRK dialogue, while internal code-page artifacts showed Korean-language build characteristics. The document contains VBA macros and an ObjectPool payload that launches certutil to download and decode Base64-staged files from handicap.eu5[.]org, then loads 32-bit or 64-bit DLL payloads and retrieves attacker-controlled configuration. ESRC links the tradecraft to earlier Konni activity, including a January 2019 Russian-language decoy document, because the macro structure, ObjectPool-hidden C2 logic and staged CAB/DLL delivery pattern closely match prior samples. The report highlights C2 and payload infrastructure such as handicap.eu5[.]org and clean.1apps[.]com, plus MD5 hashes for the analyzed documents and payloads, as evidence for defenders tracking Konni operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | handicap.eu5.org | 2019-08-19 | 2020-01-23 |
| URL | http://handicap.eu5.org/1.txt | 2019-08-19 | 2020-01-05 |
| DOMAIN | clean.1apps.com | 2019-05-24 | 2020-01-05 |
| DOMAIN | ftpupload.net | 2019-05-24 | 2020-01-05 |
| DOMAIN | 1apps.com | 2018-11-29 | 2020-01-05 |
| HASH | c313a3aca90a614dd0ff6ce28c6ae2f0 | 2019-08-19 | 2019-08-19 |
| HASH | 660a640e702606341ab0d42724380322 | 2019-08-19 | 2019-08-19 |
| URL | http://clean.1apps.com/3.txt | 2019-08-19 | 2019-08-19 |
| URL | http://handicap.eu5.org/2.txt | 2019-08-19 | 2019-08-19 |
| URL | http://clean.1apps.com/2.txt | 2019-08-19 | 2019-08-19 |
| URL | http://handicap.eu5.org/4.txt | 2019-08-19 | 2019-08-19 |
| URL | http://handicap.eu5.org/3.txt | 2019-08-19 | 2019-08-19 |
| HASH | 68b080cdc748e9357e75a65fba30eaa7 | 2019-05-24 | 2019-08-19 |
| URL | http://clean.1apps.com/4.txt | 2019-05-24 | 2019-08-19 |
| URL | http://clean.1apps.com/1.txt | 2019-05-24 | 2019-08-19 |