Konni(코니) 에서 만든 악성코드-NService_youngji057.chm(2023.11.18)
2024-01-29 • Sakai • Malware created by Konni - NService_youngji057.chm (2023.11.18) •
Konni-related malware was distributed as NService_youngji057.rar and executed through a Windows CHM file that showed a Korean-language decoy requesting a seal certificate and stamped power of attorney. The CHM embedded HTML used the Windows Help ActiveX shortcut object to create a ChromeBrowserUpdate scheduled task that launched mshta.exe against hxxp://goodmarket(.)or(.)kr/admin/sms/3(.)html every 10 minutes. The follow-on HTA and PowerShell logic contacted goodmarket(.)or(.)kr/admin/sms/net(.)php with host and username data, downloaded or uploaded files in chunks, and used obfuscated PowerShell functions for command execution and staging. The source associates Konni with North Korea-linked Thallium and APT37 activity, notes Kimsuky as a possible connection, and provides MD5, SHA-1, and SHA-256 hashes for the CHM sample.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | service.898840.com | 2024-01-29 | 2024-02-07 |
| DOMAIN | s8u.cn | 2024-01-29 | 2024-02-07 |
| HASH | 521318321221435f7f6d2f1abed8d6c… | 2024-01-29 | 2024-01-29 |
| HASH | 717d7c2ee8e97b512cbcecde3aa300c3 | 2024-01-29 | 2024-01-29 |
| HASH | 110d2f5e4e58f4209d1875dbcb5bbfa… | 2024-01-29 | 2024-01-29 |
| URL | http://goodmarket.or.kr/admin/s… | 2024-01-29 | 2024-01-29 |
| URL | http://goodmarket.or.kr/admin/s… | 2024-01-29 | 2024-01-29 |