APT-Konni 组织针对韩国近期的攻击活动分析

2024-07-08 David_Jou Analysis of recent APT-Konni attack activity targeting South Korea

https://www.freebuf.com/articles/system/405498.html

APT-Konni related activity against South Korean targets used Korean language CHM and LNK document lures to execute hidden script chains. The CHM example embeds an ActiveX object that writes Base64 content, decodes it with certutil into a VBS file, adds a Run key, and launches PowerShell to fetch remote code. A second HWP themed LNK lure searches for an embedded payload, writes it to disk, copies curl.exe as VezoQcO.exe, downloads AutoIt3.exe and an AU3 script from cavasa[.]com[.]co, and creates a scheduled task for minute by minute persistence. The source treats SUSU attribution as uncertain while tying the observed tradecraft to Konni and possible APT37 related activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 62.113.118.157 2024-07-08 2026-01-22
HASH 0aaec376904434197bae4f1a10ecfe8… 2024-07-08 2024-11-10
DOMAIN oryzanine.com 2024-03-26 2024-08-22
HASH 88b901dc2d5df59f54f02b248c24a44… 2024-07-08 2024-07-08
URL http://settlores.com/list.php?6… 2024-07-08 2024-07-08
URL http://32984.cnb39.com/code/ 2024-07-08 2024-07-08
URL http://oryzanine.com/index.php?… 2024-07-08 2024-07-08
URL http://asdlfkj.asdofji.ev/SmtIn… 2024-07-08 2024-07-08
URL https://cavasa.com.co/login 2024-07-08 2024-07-08
URL http://settlores.com/list.php?6… 2024-07-08 2024-07-08
URL http://settlores.com/get.php?63… 2024-07-08 2024-07-08
URL http://settlores.com/get.php?63… 2024-07-08 2024-07-08
URL http://settlores.com/list.php?6… 2024-07-08 2024-07-08
URL http://settlores.com/list.php?6… 2024-07-08 2024-07-08
URL http://settlores.com/list.php?6… 2024-07-08 2024-07-08
URL http://settlores.com/upload.php 2024-07-08 2024-07-08
URL http://settlores.com/list.php?f… 2024-07-08 2024-07-08
URL https://cavasa.com.co/webpyp/wp… 2024-07-08 2024-07-08
URL https://cavasa.com.co/webpyp/wp… 2024-07-08 2024-07-08
DOMAIN 32984.cnb39.com 2024-07-08 2024-07-08
DOMAIN asdlfkj.asdofji.ev 2024-07-08 2024-07-08
IPv4 5.255.109.145 2024-07-08 2024-07-08

Related Actors

Related Reports

« Back