코로나 예측 결과 위장 악성 문서(xls) 유포 중

2020-07-15 Ahnlab Malicious XLS document disguised as COVID-19 prediction results being distributed

https://asec.ahnlab.com/1355

Thumbnail for 코로나 예측 결과 위장 악성 문서(xls) 유포 중

AhnLab observed COVID-19 prediction-themed phishing distributing malicious Excel documents that entice users to enable macros with a “Predict” calculation button. The macro contains obfuscated downloader commands that use curl and certutil -decode to fetch a Base64-encoded payload from WordPress-style category.php paths such as refeeldominicana.nwideas.com/wp-content/uploads/chimps/category.php. AhnLab also linked similar HWP activity that downloads and decodes acview.dll from cooper9.com before launching it with rundll32. The payload was no longer available during analysis, but the report provides V3 detections, hashes, and related download URLs for hunting.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.cooper9.com/wp-cont… 2020-07-15 2020-07-15
URL http://refeeldominicana.nwideas… 2020-07-15 2020-07-15
DOMAIN refeeldominicana.nwideas.com 2020-07-15 2020-07-15

Related Reports

« Back