sadasd
ID: ee20e469-9245-4bb5-883f-5d250fe79dd2
STIX ID: report--ee20e469-9245-4bb5-883f-5d250fe79dd2
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2020-01-27
Last Modified Date: 2020-01-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Konni 2019 campaign analysis: this report documents multiple 2019 Konni campaigns (linked to APT37) that use malicious macro-laden Word documents to launch a multi-stage infection chain which abuses certutil and living-off-the-land binaries, employs a Vault 7-derived token impersonation/UAC bypass for privilege escalation, achieves persistence by registering a malicious DLL as the COMSysApp service DLL, performs system reconnaissance (systeminfo, tasklist), and exfiltrates gathered data to FTP-based C2 servers; the report includes decoding routines, MITRE technique mappings and extensive IOCs (file hashes, IPs, domains).
