Konni(코니) 만든 북한 시장 물가 분석 문서 위장 해서 공격 하는 악성코드-조선 시장 물가 분석(회령).hwp?(2023.11.17)

2024-02-07 Sakai Malware that attacks by disguising North Korean market price analysis documents created by Konni - North Korean market price analysis (Hoeryeong).hwp? (2023.11.17)

https://wezard4u.tistory.com/6728

Thumbnail for Konni(코니) 만든 북한 시장 물가 분석 문서 위장 해서 공격 하는 악성코드-조선 시장 물가 분석(회령).hwp?(2023.11.17)

Wezard4u analyzes a Konni malware document disguised as a Korean HWP file about North Korean market prices in Hoeryeong, suggesting targeting of people who work on North Korea-related issues. The document does not exploit an HWP vulnerability; it embeds a malicious OLE object and relies on the user clicking a read-only or editing prompt. The embedded content decompresses to reveal command infrastructure using nav.offlinedocument.site under a document-service style path, and the report provides hashes for the HWP lure, including SHA-256 d1f81eaf48b878479065d9f04a252edca193bb0ffdd7734daad2103c17a637e9. The activity fits Konni’s use of Korean-language North Korea policy lures to deliver downloader-style malware.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d1f81eaf48b878479065d9f04a252ed… 2024-02-07 2024-02-07
HASH 54b3aa4b83e410f4bf28368d59a0711b 2024-02-07 2024-02-07
URL http://nav.offlinedocument.site… 2024-02-07 2024-02-07
DOMAIN go.appp.ooguy.com 2024-02-07 2024-02-07
DOMAIN nav.offlinedocument.site 2024-02-07 2024-02-07
DOMAIN service.898840.com 2024-01-29 2024-02-07
DOMAIN s8u.cn 2024-01-29 2024-02-07
HASH b23a3738b6174f62e4696080f2d8a5f… 2024-01-22 2024-02-07

Related Actors

Related Reports

« Back