APT-Konni 组织针对韩国近期的攻击活动分析
2024-07-08 • David_Jou • Analysis of recent APT-Konni attack activity targeting South Korea •
APT-Konni related activity against South Korean targets used Korean language CHM and LNK document lures to execute hidden script chains. The CHM example embeds an ActiveX object that writes Base64 content, decodes it with certutil into a VBS file, adds a Run key, and launches PowerShell to fetch remote code. A second HWP themed LNK lure searches for an embedded payload, writes it to disk, copies curl.exe as VezoQcO.exe, downloads AutoIt3.exe and an AU3 script from cavasa[.]com[.]co, and creates a scheduled task for minute by minute persistence. The source treats SUSU attribution as uncertain while tying the observed tradecraft to Konni and possible APT37 related activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 62.113.118.157 | 2024-07-08 | 2026-01-22 |
| HASH | 0aaec376904434197bae4f1a10ecfe8… | 2024-07-08 | 2024-11-10 |
| DOMAIN | oryzanine.com | 2024-03-26 | 2024-08-22 |
| HASH | 88b901dc2d5df59f54f02b248c24a44… | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/list.php?6… | 2024-07-08 | 2024-07-08 |
| URL | http://32984.cnb39.com/code/ | 2024-07-08 | 2024-07-08 |
| URL | http://oryzanine.com/index.php?… | 2024-07-08 | 2024-07-08 |
| URL | http://asdlfkj.asdofji.ev/SmtIn… | 2024-07-08 | 2024-07-08 |
| URL | https://cavasa.com.co/login | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/list.php?6… | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/get.php?63… | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/get.php?63… | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/list.php?6… | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/list.php?6… | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/list.php?6… | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/upload.php | 2024-07-08 | 2024-07-08 |
| URL | http://settlores.com/list.php?f… | 2024-07-08 | 2024-07-08 |
| URL | https://cavasa.com.co/webpyp/wp… | 2024-07-08 | 2024-07-08 |
| URL | https://cavasa.com.co/webpyp/wp… | 2024-07-08 | 2024-07-08 |
| DOMAIN | 32984.cnb39.com | 2024-07-08 | 2024-07-08 |
| DOMAIN | asdlfkj.asdofji.ev | 2024-07-08 | 2024-07-08 |
| IPv4 | 5.255.109.145 | 2024-07-08 | 2024-07-08 |