TLP:WHITE26 IOCs
To Russia With Love: Assessing a KONNI-Backdoored Suspected Russian Consular Software Installer
Threat Actors
Diamond Model
Adversary(3)
Infrastructure(6)
Capability
Victim
5W+H Threat Analysis
Analysis unavailable
Indicators of Compromise
Indicators of Compromise26
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| Domain | p593d8g9.mygamesonline.org indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | 88zr7cua.atwebpages.com exploitintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | mhhnv7s9.myartsonline.com indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | t8nptw2h.mywebcommunity.org indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| MD5 | 7f9fad83f4e56c684c11b9fffbd047e8 file-hashindicatorintel-blog | Medium | 53 | Jun 2, 26 |
| Domain | zomfaa9a.onlinewebshop.net indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| SHA256 | 58bcd90f6f04c005c892267a3dfe91d1154d064482b07715ad5802f57c1ea32d file-hashindicatorintel-blog | Medium | 53 | Jun 2, 26 |
| Domain | jbkza9h7.atwebpages.com exploitintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | tl2j38w9.mypressonline.com indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | victory-2020.atwebpages.com indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | cor8xcib.getenjoyment.net exploitintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | mbfasq54.mypressonline.com indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| SHA256 | 9339eaf1d77bb0324e393a08a6180fe0658761fc0cd20ba25081963286dfb9c7 file-hashindicatorintel-blog | Medium | 53 | Jun 2, 26 |
| Domain | p8tebfel.getenjoyment.net exploitintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | victory-2024.mywebcommunity.org indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | 99695njd.myartsonline.com indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | 3cym4ims.medianewsonline.com indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | w9uzs9la.mywebcommunity.org indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | j1p75639.medianewsonline.com indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | 24ev0apa.scienceontheweb.net indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| SHA256 | b60dc12833110098f5eec9a51749d227db7a12d4e91a100a4fd8815695f1093f file-hashindicatorintel-blog | Medium | 53 | Jun 2, 26 |
| Domain | 5s6bqbea.sportsontheweb.net indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | g66nzt8q.mygamesonline.org indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | zcvbm1zv.onlinewebshop.net indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | c6cdg4su.sportsontheweb.net indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
| Domain | 694qf6w8.scienceontheweb.net indicatorintel-blognetwork | High | 58 | Jun 2, 26 |
IOC Relationship Graph
IOC Relationship Graph26 total IOCs
DomainMD5SHA256