Detailing Daily Domain Hunting

2022-11-23 Joe Słowik

https://pylos.co/2022/11/23/detailing-daily-domain-hunting/

Thumbnail for Detailing Daily Domain Hunting

Pylos documents a domain-hunting pivot from suspicious mail-themed infrastructure into a broader set of domains assessed as possibly linked to an in-progress Kimsuky campaign. The activity centered on East Asian, especially South Korean, hosting and spoofed services such as Google, Naver, Daum, mail, cloud, and certificate-related themes. Researchers used hosting data, SMTP/HTTP fingerprints, Let’s Encrypt certificates, JA3S values, urlscan content hashes, and passive DNS to connect related infrastructure, including onkrdot[.]info and 92.38.135.213. The report is useful for defenders tracking likely Kimsuky phishing or credential-capture infrastructure, while preserving the source’s uncertainty that no delivered threat had yet been observed.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9b43f670273b6a12b2b6894a9e29157… 2022-11-23 2025-06-17
IPv4 92.38.135.213 2022-11-23 2023-03-28
DOMAIN onkrdot.info 2022-11-23 2022-11-23
DOMAIN msn-imap.com 2022-11-23 2022-11-23

Related Actors

Related Reports

« Back