New KONNI Malware attacking Eurasia and Southeast Asia
2018-09-28 • Paloalto Networks •
Unit 42 identified NOKKI, a malware family closely related to KONNI through code and infrastructure overlap, in attacks observed from early 2018 through at least July 2018. The activity likely targeted politically motivated victims in Eurasia and possibly Southeast Asia, using Cambodian and Russian political decoys delivered as executable files, screen-saver files, and later macro-enabled Word documents. NOKKI collected victim host data, wrote artifacts such as uplog.tmp, installed payloads under local Microsoft-themed paths, and used Run-key persistence before communicating with C2 over FTP in earlier variants and HTTP in later variants. The operators relied heavily on compromised legitimate South Korean infrastructure for delivery and C2, with additional infrastructure including 101.129.1[.]104 and files.000webhost[.]com, the latter previously seen in KONNI activity. The report matters for tracking KONNI/NOKKI tradecraft because it shows a transition in delivery and C2 protocols while preserving shared development artifacts such as the zeus document author and repeated PDB paths.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | files.000webhost.com | 2018-09-28 | 2018-11-29 |
| HASH | d5fc0ef2d1ed037b5b6389882f9bb4e… | 2018-09-28 | 2018-09-28 |
| HASH | dce53e59b0c48e269dadc766a78667a… | 2018-09-28 | 2018-09-28 |
| HASH | 42fbea771f3e0ff04ac0a1d09db2a45e | 2018-09-28 | 2018-09-28 |
| HASH | c07bea0928a35b9292eebab32563378… | 2018-09-28 | 2018-09-28 |
| HASH | d92c94423ec3d01ad584a74a38a2e81… | 2018-09-28 | 2018-09-28 |
| HASH | 88587c43daff30cd3cc0c913a390e9df | 2018-09-28 | 2018-09-28 |
| HASH | 1cc8ceeef9a2ea4260fae03368a9d07… | 2018-09-28 | 2018-09-28 |
| HASH | 0657f788e89a437a1e6fe2630c19436… | 2018-09-28 | 2018-09-28 |
| HASH | b8120d5c9c2c889b37aa9e37514a3b4… | 2018-09-28 | 2018-09-28 |
| HASH | 07b90088ec02ef6757f6590a62e2a03… | 2018-09-28 | 2018-09-28 |
| HASH | d211815177ce4b9fd2d3c258d2fc628… | 2018-09-28 | 2018-09-28 |
| HASH | 5137f6a59c2c7a54f1a5fc9a9650972… | 2018-09-28 | 2018-09-28 |
| HASH | 74ddd56b1e33aa3752f143a77e5802a… | 2018-09-28 | 2018-09-28 |
| HASH | 9bf634ff0bc7c69ffceb75f9773c198… | 2018-09-28 | 2018-09-28 |
| HASH | 48f031f8120554a5f47259666fd0ee02 | 2018-09-28 | 2018-09-28 |
| HASH | dc739ca07585eab7394843bc4dba2fa… | 2018-09-28 | 2018-09-28 |
| HASH | c3172b403068aabc711b7cbe4d923ae… | 2018-09-28 | 2018-09-28 |
| HASH | 4e84f97bb61c2d373a574676fa37413… | 2018-09-28 | 2018-09-28 |
| HASH | 9b1a21d352ededd057ee3a965907126… | 2018-09-28 | 2018-09-28 |
| HASH | 02ee6302436250e1cee1e75cf452a12… | 2018-09-28 | 2018-09-28 |
| HASH | ae27e617f4197cd30cc09fe784453cd4 | 2018-09-28 | 2018-09-28 |
| HASH | 2b6b6f24f58072a02f03fa04deaccce… | 2018-09-28 | 2018-09-28 |
| HASH | 0d98ca35b29d2a9f7ca6908747c457e… | 2018-09-28 | 2018-09-28 |
| HASH | fd673703c502be907919a4ff2922b7b… | 2018-09-28 | 2018-09-28 |
| IPv4 | 145.14.145.32 | 2018-09-28 | 2018-09-28 |
| IPv4 | 141.223.125.112 | 2018-09-28 | 2018-09-28 |
| IPv4 | 210.112.239.74 | 2018-09-28 | 2018-09-28 |
| IPv4 | 101.129.1.104 | 2018-09-28 | 2018-09-28 |