법원판결 내용의 악성 엑셀(XLS) 파일 유포: 코니(KONNI) 조직
2020-07-01 • Ahnlab • Malicious Excel XLS file with court judgment content distributed by the KONNI group •
AhnLab analyzed a malicious Excel campaign whose court-judgment lure used macros to download and launch a second Excel document, then chained batch, VBS, and encoded CAB content from view-naver.com. The activity is described as sharing KONNI/Operation Moneyholic tradecraft, with the initial vector shifted from HWP to XLS. Once macros run, the malware stages mo1.bat, no1.bat, vbs.txt, mysec2.bat, and no42.bat to collect user information, upload it, register persistence through start2.vbs, and download additional payloads. Representative indicators include view-naver.com/xls paths, resulview.com, and hashes for the XLS and staged files.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4af8906f903f5de0ea98d3e323ee869c | 2020-07-01 | 2020-07-01 |
| HASH | 83478fb5d4eadb2111688953ee6cea8… | 2020-07-01 | 2020-07-01 |
| DOMAIN | view-naver.com | 2020-07-01 | 2020-07-01 |