Konni(코니) 에서 만든 국세청 사칭 악성코드-국세청 종합소득세 해명자료 제출 안내(2023.9.4)
2023-09-15 • Sakai • Malware impersonating the National Tax Service created by Konni - Guide to submitting comprehensive income tax explanation materials to the National Tax Service (September 4, 2023) •
Konni used a Korean National Tax Service themed ZIP lure that presented HWP decoy documents while hiding a malicious shortcut and script chain. The LNK ran PowerShell that searched for the shortcut, extracted XOR encoded data from it, wrote and launched payload files, then staged VBScript and batch files under C:\Users\Public\Documents. The batch logic added a Run key named svchostno2 for start.vbs persistence and repeatedly contacted ttzcloud[.]com to download a CAB payload. The source ties Konni to North Korean activity and notes overlap or possible association with Thallium, APT37, and Kimsuky, while providing hashes for the ZIP and HWP files.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6f5e4b45ca0d8c1128d27a15421eea38 | 2023-09-15 | 2024-08-22 |
| URL | http://ttzcloud.com/upload.php | 2023-09-15 | 2024-08-22 |
| DOMAIN | ttzcloud.com | 2023-09-15 | 2024-08-22 |
| HASH | d245f208d2a682f4d2c4464557973bf… | 2023-09-12 | 2024-05-20 |
| DOMAIN | resolver1.opendns.com | 2023-05-05 | 2023-12-18 |
| URL | http://ttzcloud.com/list.php?f=… | 2023-09-15 | 2023-11-24 |
| HASH | b90b0888214d2def5ab148b8d8055187 | 2023-09-15 | 2023-09-15 |
| HASH | 7f7fa98fee3cfd5b927a678e43574f4b | 2023-09-15 | 2023-09-15 |
| HASH | 6e61cab3675ba0250d0d15fd7c010000 | 2023-09-15 | 2023-09-15 |
| HASH | cabb494d8a2a36a3f653aa7900a14a9… | 2023-09-15 | 2023-09-15 |
| HASH | ddd07976e889bfc58e2925cd22e5198a | 2023-09-15 | 2023-09-15 |
| DOMAIN | buyhwan.xyz | 2023-09-15 | 2023-09-15 |
| DOMAIN | starbucks-kr.com | 2023-09-15 | 2023-09-15 |