Konni APT 利用 WinRAR 漏洞(CVE-2023-38831)首次攻击数字货币行业

2023-09-14 Knownsec Konni APT exploits WinRAR vulnerability (CVE-2023-38831) to attack the digital currency industry for the first time

https://paper.seebug.org/3032/

Thumbnail for Konni APT 利用 WinRAR 漏洞(CVE-2023-38831)首次攻击数字货币行业

Knownsec 404 reported that Konni used the WinRAR CVE-2023-38831 vulnerability in a lure archive aimed at the digital currency industry, a target set the source describes as unusual for Konni compared with Lazarus. The captured archive referenced Qbao Network and abused WinRAR handling of same-named HTML files and directories so that opening the decoy HTML executed a hidden EXE payload. The payload contacted e9f0dkd.c1.biz, staged BAT and VBS scripts, downloaded ZIP and CAB components, and used UAC bypass methods including wusa.exe token impersonation and AppInfo RPC with PPID spoofing. The final Konni RAT installed a "Remote Database Service Update" service, collected systeminfo and tasklist output, encrypted and uploaded host data, and supported remote command, file upload, and file execution functions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1536e9bf086982c072c2cba7d42b0a62 2023-09-14 2023-09-18
DOMAIN ske9dhn.c1.biz 2023-09-14 2023-09-18
DOMAIN e9f0dkd.c1.biz 2023-09-14 2023-09-18

Related Actors

Related Reports

« Back