Konni组织针对虚拟货币行业投递AutoIt恶意软件

2024-03-26 Qianxin Cyber threat report on Konni, LNK, AutoIt

https://zhuanlan.zhihu.com/p/689051421

Thumbnail for Konni组织针对虚拟货币行业投递AutoIt恶意软件

QiAnXin reports Konni activity delivering AutoIt malware to likely South Korean cryptocurrency-sector targets using lures themed around virtual-asset regulation and legal documents. The ZIP package contains a normal decoy document and a document-disguised LNK file; when opened, the LNK runs PowerShell, extracts a decoy and CAB data, and launches VBS and BAT scripts from the Public Documents directory. The scripts establish persistence through registry Run and Startup-folder changes, collect file listings and system information, encrypt URL parameters and uploads with RC4 keyed by timestamps, and communicate with infrastructure such as settlors.com. A later ZIP from the C2 deploys a compiled AutoIt script that gathers administrator status, OS version, antivirus names including Korean products, username, and hostname, then polls C2 for tasks that can download and execute EXE, DLL, BAT, PowerShell, or VBS payloads. The report links the activity to Konni based on LNK traits and malware behavior while noting prior reporting that connects Konni with APT37 and Kimsuky-related tracking.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://oryzanine.com/index.php 2024-03-26 2024-08-22
DOMAIN oryzanine.com 2024-03-26 2024-08-22
URL https://goosess.com/read/get.php 2024-03-11 2024-06-17
DOMAIN stuckss.com 2024-03-11 2024-06-17
DOMAIN goosess.com 2024-03-11 2024-06-17
HASH 1aac6272dd9b6d05fa256a89677e90b5 2024-03-26 2024-03-26
HASH e9db0e7aeb35758c6512d692e938178a 2024-03-26 2024-03-26
HASH ff44068ba6ed88e5391452cffb0983be 2024-03-26 2024-03-26
HASH 64fbf63d29cb7e8d813702a2beeee856 2024-03-26 2024-03-26
HASH 7ee77ecd79b69a082750327b5750e6e4 2024-03-26 2024-03-26
URL http://settlors.com/list.php 2024-03-26 2024-03-26
URL http://settlors.com/get.php 2024-03-26 2024-03-26
URL http://shakuss.com/upload.php 2024-03-26 2024-03-26
URL https://nasions.com/v1/read/get… 2024-03-26 2024-03-26
URL http://settlors.com/upload.php 2024-03-26 2024-03-26
URL http://shakuss.com/list.php 2024-03-26 2024-03-26
DOMAIN shakuss.com 2024-03-26 2024-03-26
DOMAIN settlors.com 2024-03-26 2024-03-26
DOMAIN nasions.com 2024-03-26 2024-03-26
HASH 655893b1641565f8ea04da4d74116b8a 2024-03-11 2024-03-26
URL http://stuckss.com/list.php 2024-03-11 2024-03-26
URL http://stuckss.com/upload.php 2024-03-11 2024-03-26

Related Actors

Related Reports

« Back