Konni(코니) 에서 만든 국세청 사칭 악성코드-첨부1.취득자금 소명대상 금액의 출처 확인서(국제조세조정에 관한 법률 시행규칙).hwp(2023.12.13)
2023-12-27 • Sakai • Malicious code impersonating the National Tax Service created by Konni - Attachment 1. Confirmation of the source of the amount subject to explanation of acquisition funds (Enforcement Rules of the International Tax Adjustment Act).hwp (December 13, 2023) •
The Wezard4u analysis covers a Konni lure that impersonated a Korean National Tax Service HWP form about acquisition fund source verification. The ZIP contained an HWP themed LNK file with embedded, heavily obfuscated PowerShell that searched for the LNK, extracted XOR encoded content, wrote a CAB file under the public user path, expanded it into a documents directory, removed the original LNK, and launched start.vbs. The post lists hashes for the ZIP and LNK and describes the activity as Konni related, while noting overlaps with Thallium, APT37, and possible Kimsuky tradecraft. The useful evidence is the Korean tax themed lure, LNK and PowerShell execution chain, and file extraction behavior rather than the large obfuscated script body itself.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fbdc74e4a2733561fa077873a008e9a… | 2023-12-27 | 2023-12-27 |
| HASH | 0ae016988c0d234f0c5ee4a003653c1… | 2023-12-27 | 2023-12-27 |
| HASH | c459315c5a7c4e014867d8e27b1209c… | 2023-12-27 | 2023-12-27 |
| HASH | ceb4847592b0b9ddc2b9c239fa48c471 | 2023-12-27 | 2023-12-27 |
| HASH | 7a86930567749d349e87b7523da26a39 | 2023-12-27 | 2023-12-27 |
| HASH | fab8d2d22d264c9b0e0d62ea311b875… | 2023-12-27 | 2023-12-27 |
| URL | http://ddsdata.net/list.php?f=%… | 2023-12-27 | 2023-12-27 |
| URL | http://ddsdata.net/upload.php | 2023-12-27 | 2023-12-27 |
| URL | https://aufildeseaux.com/wp-adm… | 2023-12-27 | 2023-12-27 |
| URL | https://aufildeseaux.com/wp-adm… | 2023-12-27 | 2023-12-27 |
| URL | https://aufildeseaux.com/wp-adm… | 2023-12-27 | 2023-12-27 |
| DOMAIN | aufildeseaux.com | 2023-12-27 | 2023-12-27 |
| DOMAIN | ddsdata.net | 2023-12-27 | 2023-12-27 |
| DOMAIN | lms.appliveko.com | 2023-12-27 | 2023-12-27 |