법원판결 내용의 악성 엑셀(XLS) 파일 유포: 코니(KONNI) 조직

2020-07-01 Ahnlab Malicious Excel XLS file with court judgment content distributed by the KONNI group

https://asec.ahnlab.com/1341

Thumbnail for 법원판결 내용의 악성 엑셀(XLS) 파일 유포: 코니(KONNI) 조직

AhnLab analyzed a malicious Excel campaign whose court-judgment lure used macros to download and launch a second Excel document, then chained batch, VBS, and encoded CAB content from view-naver.com. The activity is described as sharing KONNI/Operation Moneyholic tradecraft, with the initial vector shifted from HWP to XLS. Once macros run, the malware stages mo1.bat, no1.bat, vbs.txt, mysec2.bat, and no42.bat to collect user information, upload it, register persistence through start2.vbs, and download additional payloads. Representative indicators include view-naver.com/xls paths, resulview.com, and hashes for the XLS and staged files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4af8906f903f5de0ea98d3e323ee869c 2020-07-01 2020-07-01
HASH 83478fb5d4eadb2111688953ee6cea8… 2020-07-01 2020-07-01
DOMAIN view-naver.com 2020-07-01 2020-07-01

Related Actors

Related Reports

« Back