A Quick Look at a New KONNI RAT Variant

2017-08-15 Fortinet

https://www.fortinet.com/blog/threat-research/a-quick-look-at-a-new-konni-rat-variant.html

Thumbnail for A Quick Look at a New KONNI RAT Variant

FortiGuard Labs analyzed a new KONNI RAT variant delivered by a malicious Word document using a decoy article about North Korea, while noting that the actual victim relationship to North Korea was unclear. The document’s VB macro drops an Aspack-packed installer as stify.exe, which installs 32-bit or 64-bit KONNI DLLs under %LocalAppData%\MFAData\event and establishes persistence through rundll32.exe autorun registry entries. The RAT retains capabilities seen in earlier KONNI activity, including file upload, system discovery, screenshot capture, file search, keylogging, and clipboard grabbing. Network handling changed from prior reporting: exfiltrated data is zipped, RC4-encrypted with a hardcoded key, Base64-encoded, and sent to a C2 using a query-string format, with indicators including donkeydancehome[.]freeiz.com and a DOC download URL hosted on uphero[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 834d3b0ce76b3f62ff87b7d6f2f9cc9b 2017-08-15 2017-08-15
HASH 0914ef43125114162082a11722c4cfc3 2017-08-15 2017-08-15
HASH 38ead1e8ffd5b357e879d7cb8f467508 2017-08-15 2017-08-15
DOMAIN donkeydancehome.freeiz.com 2017-08-15 2017-08-15
DOMAIN seesionerrorwebmailattach.upher… 2017-08-15 2017-08-15

Related Actors

Related Reports

« Back