Konni(코니) 에서 만든 특허 수수료 납부 확인증 위장한 악성코드-PaymentConfirmation.chm(2023.12.29)
2024-01-17 • Sakai • Malicious code disguised as a patent fee payment confirmation created by Konni - PaymentConfirmation.chm (2023.12.29) •
The source analyzes a Konni-linked CHM file named PaymentConfirmation.chm that masquerades as a Korean patent fee payment receipt. Its embedded emlmanager.vbs launches a hidden batch file, creates or checks a SafeBrowsing scheduled task, and uses additional batch scripts to stage collection activity from C:\Users\Public\Libraries. The malware gathers system information, running processes, and Desktop and Downloads directory listings, then sends the resulting text files to niscarea.com. The report also provides hashes for the CHM sample and describes the activity as aligned with Konni, a North Korea-linked cluster associated with targeted operations since at least 2014.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://niscarea.com | 2023-11-28 | 2024-12-27 |
| DOMAIN | niscarea.com | 2023-11-28 | 2024-12-27 |
| HASH | 2548d0e05c47c506cf9fd668dace5497 | 2024-01-17 | 2024-04-05 |
| HASH | fd47c8418d9f8ed39f2f746042c982a… | 2024-01-17 | 2024-04-05 |
| HASH | 8ac21a35158ba9ebf80493bdb8cf8eb… | 2024-01-17 | 2024-04-05 |
| URL | https://niscarea.com/ | 2024-01-17 | 2024-04-05 |
| URL | https://niscarea.com/cgi-sys/su… | 2024-01-17 | 2024-01-17 |
| DOMAIN | highelp.azurewebsites.net | 2024-01-17 | 2024-01-17 |