암호화폐 내용의 Konni APT 캠페인과 '오퍼레이션 헌터 아도니스'

2019-01-02 ESTSecurity Cryptocurrency-related Konni APT campaign and ‘Operation Hunter Adonis'

http://blog.alyac.co.kr/2061

Thumbnail for 암호화폐 내용의 Konni APT 캠페인과 '오퍼레이션 헌터 아도니스'

ESRC links the Konni campaign to lure documents that historically used North Korea-related themes and, in late 2018, also impersonated policy material and cryptocurrency wallet-related documents. The documented infection chain uses malicious Word macros that fetch Base64-encoded text files, decode a CAB payload with certutil, run install.bat, and persist Word.exe via the HKCU Run key as svchost. Word.exe decodes winnet.ini and connects to 103.249.31.159:7777, checks for the fxftest string, and can receive additional commands, including installation of remote-control malware such as TeamViewer-like modules. The report notes overlap with techniques seen in Kimsuky activity and raises false-flag considerations, while listing artifacts such as filer2.1apps.com, Word.exe, winnet.ini, ADONIS account traces, and multiple PDB paths useful for tracking related Konni variants.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 103.249.31.159 2018-12-20 2019-08-29
DOMAIN filer2.1apps.com 2018-12-20 2019-06-10
URL http://filer2.1apps.com/3.txt 2019-01-02 2019-01-02
URL http://read.pudn.com/downloads6… 2019-01-02 2019-01-02
URL http://filer2.1apps.com/2.txt 2019-01-02 2019-01-02

Related Actors

Related Reports

« Back