Konni(코니) 에서 만든 특허 수수료 납부 확인증 위장한 악성코드-PaymentConfirmation.chm(2023.12.29)

2024-01-17 • Sakai • Malicious code disguised as a patent fee payment confirmation created by Konni - PaymentConfirmation.chm (2023.12.29) •

https://wezard4u.tistory.com/6711

Thumbnail for Konni(코니) 에서 만든 특허 수수료 납부 확인증 위장한 악성코드-PaymentConfirmation.chm(2023.12.29)

The source analyzes a Konni-linked CHM file named PaymentConfirmation.chm that masquerades as a Korean patent fee payment receipt. Its embedded emlmanager.vbs launches a hidden batch file, creates or checks a SafeBrowsing scheduled task, and uses additional batch scripts to stage collection activity from C:\Users\Public\Libraries. The malware gathers system information, running processes, and Desktop and Downloads directory listings, then sends the resulting text files to niscarea.com. The report also provides hashes for the CHM sample and describes the activity as aligned with Konni, a North Korea-linked cluster associated with targeted operations since at least 2014.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN niscarea.com 2023-11-28 2026-09-18
URL https://niscarea.com 2023-11-28 2024-12-27
HASH fd47c8418d9f8ed39f2f746042c982a… 2024-01-17 2024-04-05
URL https://niscarea.com/ 2024-01-17 2024-04-05
URL https://niscarea.com/cgi-sys/su… 2024-01-17 2024-01-17
DOMAIN highelp.azurewebsites.net 2024-01-17 2024-01-17

Related Actors

Related Reports

« Back