Konni(코니) 만든 북한 시장 물가 분석 문서 위장 해서 공격 하는 악성코드-주요도시 시장가격 조사 2023.xlsx(2023.12.29)
2024-01-04 • Sakai • Malware that attacks by disguising North Korean market price analysis documents created by Konni - Market price survey in major cities 2023.xlsx (2023.12.29) •
The source analyzes a Konni-attributed Excel lure named as a 2023 North Korean market price survey, aimed at people working on North Korea-related topics. Opening the spreadsheet exposes an ActiveX control warning; enabling content triggers contact with app.documentoffice.club through a URL embedded in xl/activeX1.bin. The author links the activity to the Konni cluster associated with Thallium, APT37, and possibly Kimsuky, while noting earlier use of CVE-2022-41128 in related activity. The report includes the sample hashes for the XLSX payload and warns that detection was limited at the time to a small number of Korean security products.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 39c97ca820f31e7903ccb190fee0203… | 2024-01-04 | 2024-01-22 |
| HASH | 28d25a4021536394fd890c4b6d9b5551 | 2024-01-04 | 2024-01-04 |
| HASH | 44365e0bcd77f1721d061dc03dd3c17… | 2024-01-04 | 2024-01-04 |
| URL | http://app.documentoffice.club/… | 2024-01-04 | 2024-01-04 |
| DOMAIN | app.documentoffice.club | 2024-01-04 | 2024-01-04 |
| DOMAIN | xkdgruop.com | 2024-01-04 | 2024-01-04 |