Konni(코니) 에서 만든 국세청 사칭 악성코드-국세청 종합소득세 해명자료 제출 안내(2023.9.4)

2023-09-15 Sakai Malware impersonating the National Tax Service created by Konni - Guide to submitting comprehensive income tax explanation materials to the National Tax Service (September 4, 2023)

https://wezard4u.tistory.com/6592

Thumbnail for Konni(코니) 에서 만든 국세청 사칭 악성코드-국세청 종합소득세 해명자료 제출 안내(2023.9.4)

Konni used a Korean National Tax Service themed ZIP lure that presented HWP decoy documents while hiding a malicious shortcut and script chain. The LNK ran PowerShell that searched for the shortcut, extracted XOR encoded data from it, wrote and launched payload files, then staged VBScript and batch files under C:\Users\Public\Documents. The batch logic added a Run key named svchostno2 for start.vbs persistence and repeatedly contacted ttzcloud[.]com to download a CAB payload. The source ties Konni to North Korean activity and notes overlap or possible association with Thallium, APT37, and Kimsuky, while providing hashes for the ZIP and HWP files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6f5e4b45ca0d8c1128d27a15421eea38 2023-09-15 2024-08-22
URL http://ttzcloud.com/upload.php 2023-09-15 2024-08-22
DOMAIN ttzcloud.com 2023-09-15 2024-08-22
HASH d245f208d2a682f4d2c4464557973bf… 2023-09-12 2024-05-20
DOMAIN resolver1.opendns.com 2023-05-05 2023-12-18
URL http://ttzcloud.com/list.php?f=… 2023-09-15 2023-11-24
HASH b90b0888214d2def5ab148b8d8055187 2023-09-15 2023-09-15
HASH 7f7fa98fee3cfd5b927a678e43574f4b 2023-09-15 2023-09-15
HASH 6e61cab3675ba0250d0d15fd7c010000 2023-09-15 2023-09-15
HASH cabb494d8a2a36a3f653aa7900a14a9… 2023-09-15 2023-09-15
HASH ddd07976e889bfc58e2925cd22e5198a 2023-09-15 2023-09-15
DOMAIN buyhwan.xyz 2023-09-15 2023-09-15
DOMAIN starbucks-kr.com 2023-09-15 2023-09-15

Related Actors

Related Reports

« Back