Konni(코니) 만든 북한 시장 물가 분석 문서 위장 해서 공격 하는 악성코드-주요도시 시장가격 조사 2023.xlsx(2023.12.29)

2024-01-04 Sakai Malware that attacks by disguising North Korean market price analysis documents created by Konni - Market price survey in major cities 2023.xlsx (2023.12.29)

https://wezard4u.tistory.com/6699

Thumbnail for Konni(코니) 만든 북한 시장 물가 분석 문서 위장 해서 공격 하는 악성코드-주요도시 시장가격 조사 2023.xlsx(2023.12.29)

The source analyzes a Konni-attributed Excel lure named as a 2023 North Korean market price survey, aimed at people working on North Korea-related topics. Opening the spreadsheet exposes an ActiveX control warning; enabling content triggers contact with app.documentoffice.club through a URL embedded in xl/activeX1.bin. The author links the activity to the Konni cluster associated with Thallium, APT37, and possibly Kimsuky, while noting earlier use of CVE-2022-41128 in related activity. The report includes the sample hashes for the XLSX payload and warns that detection was limited at the time to a small number of Korean security products.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 39c97ca820f31e7903ccb190fee0203… 2024-01-04 2024-01-22
HASH 28d25a4021536394fd890c4b6d9b5551 2024-01-04 2024-01-04
HASH 44365e0bcd77f1721d061dc03dd3c17… 2024-01-04 2024-01-04
URL http://app.documentoffice.club/… 2024-01-04 2024-01-04
DOMAIN app.documentoffice.club 2024-01-04 2024-01-04
DOMAIN xkdgruop.com 2024-01-04 2024-01-04

Related Actors

Related Reports

« Back