Detailing Daily Domain Hunting
2022-11-23 • Joe Słowik •
Pylos documents a domain-hunting pivot from suspicious mail-themed infrastructure into a broader set of domains assessed as possibly linked to an in-progress Kimsuky campaign. The activity centered on East Asian, especially South Korean, hosting and spoofed services such as Google, Naver, Daum, mail, cloud, and certificate-related themes. Researchers used hosting data, SMTP/HTTP fingerprints, Let’s Encrypt certificates, JA3S values, urlscan content hashes, and passive DNS to connect related infrastructure, including onkrdot[.]info and 92.38.135.213. The report is useful for defenders tracking likely Kimsuky phishing or credential-capture infrastructure, while preserving the source’s uncertainty that no delivered threat had yet been observed.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9b43f670273b6a12b2b6894a9e29157… | 2022-11-23 | 2025-06-17 |
| IPv4 | 92.38.135.213 | 2022-11-23 | 2023-03-28 |
| DOMAIN | onkrdot.info | 2022-11-23 | 2022-11-23 |
| DOMAIN | msn-imap.com | 2022-11-23 | 2022-11-23 |