Konni(코니) 에서 만든 특허 수수료 납부 확인증 위장한 악성코드-PaymentConfirmation.chm(2023.12.29)

2024-01-17 Sakai Malicious code disguised as a patent fee payment confirmation created by Konni - PaymentConfirmation.chm (2023.12.29)

https://wezard4u.tistory.com/6711

Thumbnail for Konni(코니) 에서 만든 특허 수수료 납부 확인증 위장한 악성코드-PaymentConfirmation.chm(2023.12.29)

The source analyzes a Konni-linked CHM file named PaymentConfirmation.chm that masquerades as a Korean patent fee payment receipt. Its embedded emlmanager.vbs launches a hidden batch file, creates or checks a SafeBrowsing scheduled task, and uses additional batch scripts to stage collection activity from C:\Users\Public\Libraries. The malware gathers system information, running processes, and Desktop and Downloads directory listings, then sends the resulting text files to niscarea.com. The report also provides hashes for the CHM sample and describes the activity as aligned with Konni, a North Korea-linked cluster associated with targeted operations since at least 2014.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://niscarea.com 2023-11-28 2024-12-27
DOMAIN niscarea.com 2023-11-28 2024-12-27
HASH 2548d0e05c47c506cf9fd668dace5497 2024-01-17 2024-04-05
HASH fd47c8418d9f8ed39f2f746042c982a… 2024-01-17 2024-04-05
HASH 8ac21a35158ba9ebf80493bdb8cf8eb… 2024-01-17 2024-04-05
URL https://niscarea.com/ 2024-01-17 2024-04-05
URL https://niscarea.com/cgi-sys/su… 2024-01-17 2024-01-17
DOMAIN highelp.azurewebsites.net 2024-01-17 2024-01-17

Related Actors

Related Reports

« Back