Konni APT 利用 WinRAR 漏洞(CVE-2023-38831)首次攻击数字货币行业
2023-09-14 • Knownsec • Konni APT exploits WinRAR vulnerability (CVE-2023-38831) to attack the digital currency industry for the first time •
Knownsec 404 reported that Konni used the WinRAR CVE-2023-38831 vulnerability in a lure archive aimed at the digital currency industry, a target set the source describes as unusual for Konni compared with Lazarus. The captured archive referenced Qbao Network and abused WinRAR handling of same-named HTML files and directories so that opening the decoy HTML executed a hidden EXE payload. The payload contacted e9f0dkd.c1.biz, staged BAT and VBS scripts, downloaded ZIP and CAB components, and used UAC bypass methods including wusa.exe token impersonation and AppInfo RPC with PPID spoofing. The final Konni RAT installed a "Remote Database Service Update" service, collected systeminfo and tasklist output, encrypted and uploaded host data, and supported remote command, file upload, and file execution functions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1536e9bf086982c072c2cba7d42b0a62 | 2023-09-14 | 2023-09-18 |
| DOMAIN | ske9dhn.c1.biz | 2023-09-14 | 2023-09-18 |
| DOMAIN | e9f0dkd.c1.biz | 2023-09-14 | 2023-09-18 |