林林总总,2022年中Konni组织针对东欧及东亚地区的攻击活动分析 - 安恒威胁情报中心

2022-11-16 安恒信息 All kinds of things, analysis of Konni organization's attack activities targeting Eastern Europe and East Asia in mid-2022 - Anheng Threat Intelligence Center

https://starmap.dbappsecurity.com.cn/blog/articles/2022/11/16/konni-2022/

Thumbnail for 林林总总,2022年中Konni组织针对东欧及东亚地区的攻击活动分析 - 安恒威胁情报中心

DBAPPSecurity analyzes Konni activity targeting Eastern Europe and East Asia in mid-2022, including samples submitted from South Korea and Russia. The report links the activity through traffic patterns, targeting, and later-stage payloads, and notes that Korean submissions included cryptocurrency-sector targeting while Russian submissions used diplomatic lures involving Russia, Korea, North Korea, and the United States. Konni used varied initial loaders, including macro documents, CHM files, and encrypted configuration files, then collected system information, compressed it, and uploaded it to C2 infrastructure. The actor also issued follow-on commands to download or execute additional payloads, demonstrating a flexible espionage workflow.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 705c8d431b4b8fa834491ff6975a0532 2022-11-16 2024-09-05
HASH 28942e7704b629c63afefe23d38068f5 2022-11-16 2024-09-05
HASH cf5f18032667bfb4c7373191e7fb1fbf 2022-11-16 2024-09-05
HASH 00e6e9ed4666623860686c123ed334f0 2022-11-16 2024-09-05
HASH 66fba06e965f9a6ea192db7f452ea9b6 2022-11-16 2024-09-05
DOMAIN 968796.c1.biz 2022-11-16 2024-09-05
DOMAIN word2022.c1.biz 2022-09-28 2024-09-05
HASH dae0efd29230feab95f46ee20030a425 2022-08-26 2024-09-05
DOMAIN gg1593.c1.biz 2022-08-26 2024-09-05
DOMAIN c1.biz 2020-01-23 2024-09-05
HASH 093878920b7a70b1c4dcb953362a319c 2022-11-16 2022-11-16
HASH 320d2e841d145f48f513eba516c1e796 2022-11-16 2022-11-16
HASH 24ef6a627d69f6bfe4b8325f74a8adba 2022-11-16 2022-11-16
HASH de8cd8c065faf36f033437f335caf5ba 2022-11-16 2022-11-16
HASH b06ab8e1e7c75d883ae2994644a9d9b3 2022-11-16 2022-11-16
HASH f71631e9253193396ad897ae4c3ec623 2022-11-16 2022-11-16
DOMAIN 687964.c1.biz 2022-11-16 2022-11-16

Related Actors

Related Reports

« Back