Konni(코니) 에서 만든 악성코드-NService_youngji057.chm(2023.11.18)

2024-01-29 Sakai Malware created by Konni - NService_youngji057.chm (2023.11.18)

https://wezard4u.tistory.com/6721

Thumbnail for Konni(코니) 에서 만든 악성코드-NService_youngji057.chm(2023.11.18)

Konni-related malware was distributed as NService_youngji057.rar and executed through a Windows CHM file that showed a Korean-language decoy requesting a seal certificate and stamped power of attorney. The CHM embedded HTML used the Windows Help ActiveX shortcut object to create a ChromeBrowserUpdate scheduled task that launched mshta.exe against hxxp://goodmarket(.)or(.)kr/admin/sms/3(.)html every 10 minutes. The follow-on HTA and PowerShell logic contacted goodmarket(.)or(.)kr/admin/sms/net(.)php with host and username data, downloaded or uploaded files in chunks, and used obfuscated PowerShell functions for command execution and staging. The source associates Konni with North Korea-linked Thallium and APT37 activity, notes Kimsuky as a possible connection, and provides MD5, SHA-1, and SHA-256 hashes for the CHM sample.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN service.898840.com 2024-01-29 2024-02-07
DOMAIN s8u.cn 2024-01-29 2024-02-07
HASH 521318321221435f7f6d2f1abed8d6c… 2024-01-29 2024-01-29
HASH 717d7c2ee8e97b512cbcecde3aa300c3 2024-01-29 2024-01-29
HASH 110d2f5e4e58f4209d1875dbcb5bbfa… 2024-01-29 2024-01-29
URL http://goodmarket.or.kr/admin/s… 2024-01-29 2024-01-29
URL http://goodmarket.or.kr/admin/s… 2024-01-29 2024-01-29

Related Actors

Related Reports

« Back