북한 해킹 단체 Konni(코니) 암호화폐 거래소 빗썸(Bithumb) 정보 업데이트 요청으로 위장한 악성코드-금융당국 요청에 따른 프로젝트
Tags
attack-pattern: | Powershell - T1059.001 Python - T1059.006 Software - T1592.002 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 7b3fa0f1-e567-4f5f-9ad4-8dbe3f041ed6 |
Fingerprint | 70e3e5554b0bd272 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | July 25, 2024, midnight |
Added to db | Aug. 31, 2024, 11:18 a.m. |
Last updated | Dec. 19, 2024, 1:32 p.m. |
Headline | 꿈을꾸는 파랑새 |
Title | 북한 해킹 단체 Konni(코니) 암호화폐 거래소 빗썸(Bithumb) 정보 업데이트 요청으로 위장한 악성코드-금융당국 요청에 따른 프로젝트 |
Detected Hints/Tags/Attributes | 37/1/26 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://wezard4u.tistory.com/429239 |
Details | Source | http://wezard4u.tistory.com/429239 |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 478 | ✔ | 꿈을꾸는 파랑새 | https://wezard4u.tistory.com/feed | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 13 | trojan.link |
|
Details | File | 1 | 건.zip |
|
Details | File | 1 | 요청사항.xlsx |
|
Details | File | 1 | 건.pdf |
|
Details | File | 23 | start.vbs |
|
Details | File | 2 | dp0d1.txt |
|
Details | File | 2 | dp0d2.txt |
|
Details | File | 2 | dp0d3.txt |
|
Details | File | 2 | dp0d4.txt |
|
Details | File | 1 | 90262621.bat |
|
Details | File | 3 | d1.txt |
|
Details | File | 2 | %computername%_down.txt |
|
Details | File | 3 | d2.txt |
|
Details | File | 2 | %computername%_docu.txt |
|
Details | File | 3 | d3.txt |
|
Details | File | 2 | %computername%_desk.txt |
|
Details | File | 3 | d4.txt |
|
Details | File | 2 | %computername%_sys.txt |
|
Details | File | 4 | 3.sys |
|
Details | File | 9 | -ud123.bat |
|
Details | md5 | 1 | 6155d592e9083937ae5dadb304a69053 |
|
Details | md5 | 1 | e3eeeebb117b7c3128d87b6e027bd85d |
|
Details | sha1 | 1 | 0e491c00e5c4be460cb4632d96e4963e16c487a2 |
|
Details | sha1 | 1 | d3c78ad4977d486defeb72f888e3f0c4231ef5d8 |
|
Details | sha256 | 1 | 65bc642b1c454d314ad71c5f4a2348f9fbb5d290f6a21f6a5028d852427f5b1a |
|
Details | sha256 | 1 | 3a2d628db6cd2a526ee908d3a4763b167f517ba18c9af86846e016b8d9221397 |