New KONNI Malware attacking Eurasia and Southeast Asia

2018-09-28 Paloalto Networks

https://researchcenter.paloaltonetworks.com/2018/09/unit42-new-konni-malware-attacking-eurasia-southeast-asia/

Thumbnail for New KONNI Malware attacking Eurasia and Southeast Asia

Unit 42 identified NOKKI, a malware family closely related to KONNI through code and infrastructure overlap, in attacks observed from early 2018 through at least July 2018. The activity likely targeted politically motivated victims in Eurasia and possibly Southeast Asia, using Cambodian and Russian political decoys delivered as executable files, screen-saver files, and later macro-enabled Word documents. NOKKI collected victim host data, wrote artifacts such as uplog.tmp, installed payloads under local Microsoft-themed paths, and used Run-key persistence before communicating with C2 over FTP in earlier variants and HTTP in later variants. The operators relied heavily on compromised legitimate South Korean infrastructure for delivery and C2, with additional infrastructure including 101.129.1[.]104 and files.000webhost[.]com, the latter previously seen in KONNI activity. The report matters for tracking KONNI/NOKKI tradecraft because it shows a transition in delivery and C2 protocols while preserving shared development artifacts such as the zeus document author and repeated PDB paths.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN files.000webhost.com 2018-09-28 2018-11-29
HASH d5fc0ef2d1ed037b5b6389882f9bb4e… 2018-09-28 2018-09-28
HASH dce53e59b0c48e269dadc766a78667a… 2018-09-28 2018-09-28
HASH 42fbea771f3e0ff04ac0a1d09db2a45e 2018-09-28 2018-09-28
HASH c07bea0928a35b9292eebab32563378… 2018-09-28 2018-09-28
HASH d92c94423ec3d01ad584a74a38a2e81… 2018-09-28 2018-09-28
HASH 88587c43daff30cd3cc0c913a390e9df 2018-09-28 2018-09-28
HASH 1cc8ceeef9a2ea4260fae03368a9d07… 2018-09-28 2018-09-28
HASH 0657f788e89a437a1e6fe2630c19436… 2018-09-28 2018-09-28
HASH b8120d5c9c2c889b37aa9e37514a3b4… 2018-09-28 2018-09-28
HASH 07b90088ec02ef6757f6590a62e2a03… 2018-09-28 2018-09-28
HASH d211815177ce4b9fd2d3c258d2fc628… 2018-09-28 2018-09-28
HASH 5137f6a59c2c7a54f1a5fc9a9650972… 2018-09-28 2018-09-28
HASH 74ddd56b1e33aa3752f143a77e5802a… 2018-09-28 2018-09-28
HASH 9bf634ff0bc7c69ffceb75f9773c198… 2018-09-28 2018-09-28
HASH 48f031f8120554a5f47259666fd0ee02 2018-09-28 2018-09-28
HASH dc739ca07585eab7394843bc4dba2fa… 2018-09-28 2018-09-28
HASH c3172b403068aabc711b7cbe4d923ae… 2018-09-28 2018-09-28
HASH 4e84f97bb61c2d373a574676fa37413… 2018-09-28 2018-09-28
HASH 9b1a21d352ededd057ee3a965907126… 2018-09-28 2018-09-28
HASH 02ee6302436250e1cee1e75cf452a12… 2018-09-28 2018-09-28
HASH ae27e617f4197cd30cc09fe784453cd4 2018-09-28 2018-09-28
HASH 2b6b6f24f58072a02f03fa04deaccce… 2018-09-28 2018-09-28
HASH 0d98ca35b29d2a9f7ca6908747c457e… 2018-09-28 2018-09-28
HASH fd673703c502be907919a4ff2922b7b… 2018-09-28 2018-09-28
IPv4 145.14.145.32 2018-09-28 2018-09-28
IPv4 141.223.125.112 2018-09-28 2018-09-28
IPv4 210.112.239.74 2018-09-28 2018-09-28
IPv4 101.129.1.104 2018-09-28 2018-09-28

Related Actors

Related Reports

« Back