Konni(코니) 북한대학원대학교 타겟으로 만든 악성코드-2023-2-주차등록신청서-학생용.hwp(2023.8.30)

2023-09-01 Sakai Konni (Konni) Malicious code created targeting North Korean Graduate School - 2023-2 - Parking registration application - for students.hwp (2023.8.30)

https://wezard4u.tistory.com/6574

Thumbnail for Konni(코니) 북한대학원대학교 타겟으로 만든 악성코드-2023-2-주차등록신청서-학생용.hwp(2023.8.30)

The source analyzes Konni malware disguised as HWP-themed LNK files targeting Korea National University of North Korean Studies, likely aiming at faculty or students involved in North Korea-focused education and consulting. The malware was delivered inside nested compressed archives and used filenames such as “2023-2 parking registration application” and “course registration correction form” to make shortcut files appear like Korean document files. Execution ran hidden PowerShell that located the LNK by size, carved out and opened a decoy HWP document, extracted update_cmd.zip into the Public Documents directory, and launched update.vbs. The report emphasizes the double-compressed delivery, HWP/LNK masquerading, and embedded PowerShell/VBS chain rather than providing a full C2 description in the excerpt.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dd85c8400fb30e4d02f0159aab3c3db… 2023-09-01 2023-11-24
URL http://anrun.kr/movie/contents.… 2023-09-01 2023-11-24
DOMAIN anrun.kr 2023-09-01 2023-11-24
HASH d7d48592bc21b37c02891e0e036bf26c 2023-09-01 2023-09-26
HASH b86c38ae5c24c55831d7f8ca3cbeb814 2023-09-01 2023-09-26
HASH 26f69f8917f6890f26ec5b10611df092 2023-09-01 2023-09-26
HASH 892bd45372876d29e883e114981e311b 2023-09-01 2023-09-26
HASH ff4067b4865c9b49da2f28ac12ca5c1a 2023-09-01 2023-09-26
HASH db31a36e1684c568fa3529d60a59ba29 2023-09-01 2023-09-26
HASH 4c1d53a52d505f4e0646e3e086aa4b0… 2023-09-01 2023-09-01
HASH 207ef77e5991486a97bdec6939b9592… 2023-09-01 2023-09-01
HASH 484323e010793b16594c9d92694ea1e… 2023-09-01 2023-09-01
HASH 6125a6e8c160df9a33549927f97316df 2023-09-01 2023-09-01
HASH 4bd6c089537d8ac66ac147b1512e7634 2023-09-01 2023-09-01
HASH 17d7aa84e33ea5d504c39a784007d4a… 2023-09-01 2023-09-01
HASH f699520c4eabe3745f59cccabfc6020… 2023-09-01 2023-09-01
HASH 3e798a107d354a0f106465b564c0d0b… 2023-09-01 2023-09-01
HASH b791cf55ac70224c5e7c98167bf497c… 2023-09-01 2023-09-01
URL http://anrun.kr 2023-09-01 2023-09-01

Related Actors

Related Reports

« Back