Skip to main content

Kunai Analysis Report - Malware Sample Abusing Open Recursive DNS for Exfiltration

0
Medium
Published: 12/15/2025 (12/15/2025, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Kunai Analysis Report - Malware Sample Abusing Open Recursive DNS for Exfiltration

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 15:36:30 UTC

Technical Analysis

The Kunai Analysis Report details a malware sample that leverages open recursive DNS servers to perform data exfiltration. This technique involves sending data through DNS queries to external recursive resolvers, bypassing some traditional network defenses. The report does not specify affected software versions or known active exploitation. The malware's use of DNS for exfiltration aligns with the MITRE ATT&CK pattern T1438 (Exfiltration Over Other Network Medium).

Potential Impact

The primary impact is unauthorized data exfiltration through open recursive DNS servers, which can lead to data leakage from compromised systems. There are no reports of active exploitation or direct system compromise beyond the exfiltration vector. The threat may evade detection by using DNS traffic, which is often allowed through firewalls.

Defensive Guidance

No patch is available for this malware sample. Mitigation should focus on restricting access to open recursive DNS servers within the network and monitoring DNS traffic for unusual patterns. Since this is a malware behavior report rather than a vulnerability in software, remediation involves network configuration and monitoring rather than patching. No vendor advisory or official fix is provided.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
9c2ec5f6-afa1-4753-891b-d130b4539648
Original Timestamp
1765803222

Indicators of Compromise

Text

ValueDescriptionCopy
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP
textAF_INET
textTCP

Ip

ValueDescriptionCopy
ip8.8.8.8
ip8.8.4.4
ip9.9.9.9
ip45.90.28.160
ip45.90.30.160
ip149.112.112.112
ip9.9.9.11
ip1.1.1.1
ip1.0.0.1
ip149.112.112.11

Port

ValueDescriptionCopy
port443
port443
port443
port443
port443
port443
port443
port443
port443
port443

Domain

ValueDescriptionCopy
domainservice.systemsvcs.com
domainservice.systemsvcs.com

Datetime

ValueDescriptionCopy
datetime2025-12-15T10:44:44.964728+00:00
datetime2025-12-15T10:44:44.965450+00:00

File

ValueDescriptionCopy
filebb71e285-75ad-4682-8fe7-903b0742e3a0
fileactivity-graph.svg
sample activity graph
filekunai.json.gz
kunai logs for sample

Size in-bytes

ValueDescriptionCopy
size-in-bytes5976064

Float

ValueDescriptionCopy
float6.0021875680609

Hash

ValueDescriptionCopy
hash9c44bc9373377831c45dd0ac2661a28e
hashb439749a581ac5a29b5c9d91fc092bf4ceaa76a4
hash320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759
hasha4e6614000d02dcaa8f18bf34f630f7b7c4c6b00bd4251144a961e67b4c5f71b42395910f678287b7b7b88beeb43692bfa9b618426117bdd2b4d8ebf54d6e309

Malware sample

ValueDescriptionCopy
malware-samplebb71e285-75ad-4682-8fe7-903b0742e3a0|9c44bc9373377831c45dd0ac2661a28e

Threat ID: 69405ab7d9bcdf3f3dfb1be4

Added to database: 12/15/2025, 19:00:07 UTC

Last enriched: 07/30/2026, 15:36:30 UTC

Last updated: 09/09/2026, 15:36:46 UTC

Views: 2013

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses