Konni(코니) 에서 만든 국세청 사칭 악성코드-첨부1.취득자금 소명대상 금액의 출처 확인서(국제조세조정에 관한 법률 시행규칙).hwp(2023.12.13)

2023-12-27 Sakai Malicious code impersonating the National Tax Service created by Konni - Attachment 1. Confirmation of the source of the amount subject to explanation of acquisition funds (Enforcement Rules of the International Tax Adjustment Act).hwp (December 13, 2023)

https://wezard4u.tistory.com/6693

Thumbnail for Konni(코니) 에서 만든 국세청 사칭 악성코드-첨부1.취득자금 소명대상 금액의 출처 확인서(국제조세조정에 관한 법률 시행규칙).hwp(2023.12.13)

The Wezard4u analysis covers a Konni lure that impersonated a Korean National Tax Service HWP form about acquisition fund source verification. The ZIP contained an HWP themed LNK file with embedded, heavily obfuscated PowerShell that searched for the LNK, extracted XOR encoded content, wrote a CAB file under the public user path, expanded it into a documents directory, removed the original LNK, and launched start.vbs. The post lists hashes for the ZIP and LNK and describes the activity as Konni related, while noting overlaps with Thallium, APT37, and possible Kimsuky tradecraft. The useful evidence is the Korean tax themed lure, LNK and PowerShell execution chain, and file extraction behavior rather than the large obfuscated script body itself.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fbdc74e4a2733561fa077873a008e9a… 2023-12-27 2023-12-27
HASH 0ae016988c0d234f0c5ee4a003653c1… 2023-12-27 2023-12-27
HASH c459315c5a7c4e014867d8e27b1209c… 2023-12-27 2023-12-27
HASH ceb4847592b0b9ddc2b9c239fa48c471 2023-12-27 2023-12-27
HASH 7a86930567749d349e87b7523da26a39 2023-12-27 2023-12-27
HASH fab8d2d22d264c9b0e0d62ea311b875… 2023-12-27 2023-12-27
URL http://ddsdata.net/list.php?f=%… 2023-12-27 2023-12-27
URL http://ddsdata.net/upload.php 2023-12-27 2023-12-27
URL https://aufildeseaux.com/wp-adm… 2023-12-27 2023-12-27
URL https://aufildeseaux.com/wp-adm… 2023-12-27 2023-12-27
URL https://aufildeseaux.com/wp-adm… 2023-12-27 2023-12-27
DOMAIN aufildeseaux.com 2023-12-27 2023-12-27
DOMAIN ddsdata.net 2023-12-27 2023-12-27
DOMAIN lms.appliveko.com 2023-12-27 2023-12-27

Related Actors

Related Reports

« Back