Konni组织针对虚拟货币行业投递AutoIt恶意软件
2024-03-26 • Qianxin • Cyber threat report on Konni, LNK, AutoIt •
QiAnXin reports Konni activity delivering AutoIt malware to likely South Korean cryptocurrency-sector targets using lures themed around virtual-asset regulation and legal documents. The ZIP package contains a normal decoy document and a document-disguised LNK file; when opened, the LNK runs PowerShell, extracts a decoy and CAB data, and launches VBS and BAT scripts from the Public Documents directory. The scripts establish persistence through registry Run and Startup-folder changes, collect file listings and system information, encrypt URL parameters and uploads with RC4 keyed by timestamps, and communicate with infrastructure such as settlors.com. A later ZIP from the C2 deploys a compiled AutoIt script that gathers administrator status, OS version, antivirus names including Korean products, username, and hostname, then polls C2 for tasks that can download and execute EXE, DLL, BAT, PowerShell, or VBS payloads. The report links the activity to Konni based on LNK traits and malware behavior while noting prior reporting that connects Konni with APT37 and Kimsuky-related tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://oryzanine.com/index.php | 2024-03-26 | 2024-08-22 |
| DOMAIN | oryzanine.com | 2024-03-26 | 2024-08-22 |
| URL | https://goosess.com/read/get.php | 2024-03-11 | 2024-06-17 |
| DOMAIN | stuckss.com | 2024-03-11 | 2024-06-17 |
| DOMAIN | goosess.com | 2024-03-11 | 2024-06-17 |
| HASH | 1aac6272dd9b6d05fa256a89677e90b5 | 2024-03-26 | 2024-03-26 |
| HASH | e9db0e7aeb35758c6512d692e938178a | 2024-03-26 | 2024-03-26 |
| HASH | ff44068ba6ed88e5391452cffb0983be | 2024-03-26 | 2024-03-26 |
| HASH | 64fbf63d29cb7e8d813702a2beeee856 | 2024-03-26 | 2024-03-26 |
| HASH | 7ee77ecd79b69a082750327b5750e6e4 | 2024-03-26 | 2024-03-26 |
| URL | http://settlors.com/list.php | 2024-03-26 | 2024-03-26 |
| URL | http://settlors.com/get.php | 2024-03-26 | 2024-03-26 |
| URL | http://shakuss.com/upload.php | 2024-03-26 | 2024-03-26 |
| URL | https://nasions.com/v1/read/get… | 2024-03-26 | 2024-03-26 |
| URL | http://settlors.com/upload.php | 2024-03-26 | 2024-03-26 |
| URL | http://shakuss.com/list.php | 2024-03-26 | 2024-03-26 |
| DOMAIN | shakuss.com | 2024-03-26 | 2024-03-26 |
| DOMAIN | settlors.com | 2024-03-26 | 2024-03-26 |
| DOMAIN | nasions.com | 2024-03-26 | 2024-03-26 |
| HASH | 655893b1641565f8ea04da4d74116b8a | 2024-03-11 | 2024-03-26 |
| URL | http://stuckss.com/list.php | 2024-03-11 | 2024-03-26 |
| URL | http://stuckss.com/upload.php | 2024-03-11 | 2024-03-26 |