A Quick Look at a New KONNI RAT Variant
2017-08-15 • Fortinet •
https://www.fortinet.com/blog/threat-research/a-quick-look-at-a-new-konni-rat-variant.html
FortiGuard Labs analyzed a new KONNI RAT variant delivered by a malicious Word document using a decoy article about North Korea, while noting that the actual victim relationship to North Korea was unclear. The document’s VB macro drops an Aspack-packed installer as stify.exe, which installs 32-bit or 64-bit KONNI DLLs under %LocalAppData%\MFAData\event and establishes persistence through rundll32.exe autorun registry entries. The RAT retains capabilities seen in earlier KONNI activity, including file upload, system discovery, screenshot capture, file search, keylogging, and clipboard grabbing. Network handling changed from prior reporting: exfiltrated data is zipped, RC4-encrypted with a hardcoded key, Base64-encoded, and sent to a C2 using a query-string format, with indicators including donkeydancehome[.]freeiz.com and a DOC download URL hosted on uphero[.]com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 834d3b0ce76b3f62ff87b7d6f2f9cc9b | 2017-08-15 | 2017-08-15 |
| HASH | 0914ef43125114162082a11722c4cfc3 | 2017-08-15 | 2017-08-15 |
| HASH | 38ead1e8ffd5b357e879d7cb8f467508 | 2017-08-15 | 2017-08-15 |
| DOMAIN | donkeydancehome.freeiz.com | 2017-08-15 | 2017-08-15 |
| DOMAIN | seesionerrorwebmailattach.upher… | 2017-08-15 | 2017-08-15 |