林林总总,2022年中Konni组织针对东欧及东亚地区的攻击活动分析 - 安恒威胁情报中心
2022-11-16 • 安恒信息 • All kinds of things, analysis of Konni organization's attack activities targeting Eastern Europe and East Asia in mid-2022 - Anheng Threat Intelligence Center •
https://starmap.dbappsecurity.com.cn/blog/articles/2022/11/16/konni-2022/
DBAPPSecurity analyzes Konni activity targeting Eastern Europe and East Asia in mid-2022, including samples submitted from South Korea and Russia. The report links the activity through traffic patterns, targeting, and later-stage payloads, and notes that Korean submissions included cryptocurrency-sector targeting while Russian submissions used diplomatic lures involving Russia, Korea, North Korea, and the United States. Konni used varied initial loaders, including macro documents, CHM files, and encrypted configuration files, then collected system information, compressed it, and uploaded it to C2 infrastructure. The actor also issued follow-on commands to download or execute additional payloads, demonstrating a flexible espionage workflow.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 705c8d431b4b8fa834491ff6975a0532 | 2022-11-16 | 2024-09-05 |
| HASH | 28942e7704b629c63afefe23d38068f5 | 2022-11-16 | 2024-09-05 |
| HASH | cf5f18032667bfb4c7373191e7fb1fbf | 2022-11-16 | 2024-09-05 |
| HASH | 00e6e9ed4666623860686c123ed334f0 | 2022-11-16 | 2024-09-05 |
| HASH | 66fba06e965f9a6ea192db7f452ea9b6 | 2022-11-16 | 2024-09-05 |
| DOMAIN | 968796.c1.biz | 2022-11-16 | 2024-09-05 |
| DOMAIN | word2022.c1.biz | 2022-09-28 | 2024-09-05 |
| HASH | dae0efd29230feab95f46ee20030a425 | 2022-08-26 | 2024-09-05 |
| DOMAIN | gg1593.c1.biz | 2022-08-26 | 2024-09-05 |
| DOMAIN | c1.biz | 2020-01-23 | 2024-09-05 |
| HASH | 093878920b7a70b1c4dcb953362a319c | 2022-11-16 | 2022-11-16 |
| HASH | 320d2e841d145f48f513eba516c1e796 | 2022-11-16 | 2022-11-16 |
| HASH | 24ef6a627d69f6bfe4b8325f74a8adba | 2022-11-16 | 2022-11-16 |
| HASH | de8cd8c065faf36f033437f335caf5ba | 2022-11-16 | 2022-11-16 |
| HASH | b06ab8e1e7c75d883ae2994644a9d9b3 | 2022-11-16 | 2022-11-16 |
| HASH | f71631e9253193396ad897ae4c3ec623 | 2022-11-16 | 2022-11-16 |
| DOMAIN | 687964.c1.biz | 2022-11-16 | 2022-11-16 |