Threat Advisory
Image Description
Common Information
Type Value
UUID e1ccb142-5a05-4c3b-bbe2-a21bf8290a20
Fingerprint 619c7007b956cbeae7bb0f2f723de264a739e3ba37f6d7564035e468254b109f
Analysis status DONE
Considered CTI value 2
Text language
Published Nov. 24, 2023, 6:15 p.m.
Added to db Feb. 7, 2024, 7:30 p.m.
Last updated Aug. 31, 2024, 2:35 a.m.
Headline Threat Advisory
Title Threat Advisory
Detected Hints/Tags/Attributes 70/3/44
Attributes
Details Type #Events CTI Value
Details Domain 3
kmdqj1.c1.biz
Details Domain 2
ouvxu2.c1.biz
Details Domain 2
9b31n8.c1.biz
Details Domain 2
3pl0y5.c1.biz
Details Domain 2
dpgbep.c1.biz
Details Domain 2
7qnbae.c1.biz
Details Domain 2
glws5m.c1.biz
Details Domain 2
ewqqa4.c1.biz
Details Domain 2
3897lb.c1.biz
Details Domain 2
558ga9.c1.biz
Details Domain 2
b91stf.c1.biz
Details Domain 2
bg5pl1.c1.biz
Details Domain 2
caoy9n.c1.biz
Details Domain 2
rziju6.c1.biz
Details Domain 2
pm90p1.c1.biz
Details Domain 2
pxyunf.c1.biz
Details Domain 2
m2jymd.c1.biz
Details Domain 2
aocsff.c1.biz
Details Domain 2
6e2nbc.c1.biz
Details Domain 2
vqt9i1.c1.biz
Details Domain 144
www.fortinet.com
Details Domain 435
www.hivepro.com
Details File 2
oleformat.ico
Details File 14
check.bat
Details File 2
netpp.bat
Details File 2
wpns.dll
Details File 41
wusa.exe
Details MITRE ATT&CK Techniques 164
T1574
Details MITRE ATT&CK Techniques 627
T1027
Details MITRE ATT&CK Techniques 116
T1134
Details MITRE ATT&CK Techniques 78
T1569
Details MITRE ATT&CK Techniques 122
T1543
Details MITRE ATT&CK Techniques 180
T1543.003
Details MITRE ATT&CK Techniques 1006
T1082
Details MITRE ATT&CK Techniques 695
T1059
Details MITRE ATT&CK Techniques 137
T1059.005
Details MITRE ATT&CK Techniques 420
T1204
Details MITRE ATT&CK Techniques 365
T1204.002
Details MITRE ATT&CK Techniques 157
T1560
Details MITRE ATT&CK Techniques 78
T1548
Details MITRE ATT&CK Techniques 409
T1566
Details MITRE ATT&CK Techniques 504
T1140
Details MITRE ATT&CK Techniques 207
T1547
Details Url 1
https://www.fortinet.com/blog/threat-research/konni-campaign-distributed-via-malicious-