Konni(코니) 만든 북한 시장 물가 분석 문서 위장 해서 공격 하는 악성코드-조선 시장 물가 분석(회령).hwp?(2023.11.17)
2024-02-07 • Sakai • Malware that attacks by disguising North Korean market price analysis documents created by Konni - North Korean market price analysis (Hoeryeong).hwp? (2023.11.17) •
Wezard4u analyzes a Konni malware document disguised as a Korean HWP file about North Korean market prices in Hoeryeong, suggesting targeting of people who work on North Korea-related issues. The document does not exploit an HWP vulnerability; it embeds a malicious OLE object and relies on the user clicking a read-only or editing prompt. The embedded content decompresses to reveal command infrastructure using nav.offlinedocument.site under a document-service style path, and the report provides hashes for the HWP lure, including SHA-256 d1f81eaf48b878479065d9f04a252edca193bb0ffdd7734daad2103c17a637e9. The activity fits Konni’s use of Korean-language North Korea policy lures to deliver downloader-style malware.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d1f81eaf48b878479065d9f04a252ed… | 2024-02-07 | 2024-02-07 |
| HASH | 54b3aa4b83e410f4bf28368d59a0711b | 2024-02-07 | 2024-02-07 |
| URL | http://nav.offlinedocument.site… | 2024-02-07 | 2024-02-07 |
| DOMAIN | go.appp.ooguy.com | 2024-02-07 | 2024-02-07 |
| DOMAIN | nav.offlinedocument.site | 2024-02-07 | 2024-02-07 |
| DOMAIN | service.898840.com | 2024-01-29 | 2024-02-07 |
| DOMAIN | s8u.cn | 2024-01-29 | 2024-02-07 |
| HASH | b23a3738b6174f62e4696080f2d8a5f… | 2024-01-22 | 2024-02-07 |