Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- The method I use for deobfuscating the ZLoader Excel 4 macros and getting the payload URLs still works:
- 1. Open the document and do not enable macros
- 2. To reveal the hidden macro sheet, go to the VB Editor and open the Immediate Window (CTRL-G)
- 3. Type the following and hit Enter:
- for each ws in sheets:ws.visible=true:next
- 4. On the newly visible macro sheet, find the cell that reads =GOTO(C1) (or whatever the value is)
- 5. Also there should be a cell above the =GOTO cell that reads =WORKSPACE.HIDE("RandomSheetName",TRUE)
- 6. Clear the contents of both cells
- 7. Now you can enable the macros
- 8. You should see the deobfuscated macros starting in the cell that was specified in the =GOTO(C1) cell
- (before you cleared the contents of that cell - in our case it's cell C1)
- The macro shouldn't run (since you cleared the contents of the GOTO cell) but I typically do this with no connectivity
- just as a double check.
- Here are the ZLoader IOCs that I saw on 2020-04-16
- SUBJECTS OBSERVED
- Account invoice-#553438 tip
- Apr. Incoming Invoice Number #71097, Karma hive
- Case 137201: improper information in the sent document
- Case 151047: improper information in the accepted statement
- Case 197782: improper information in the sent statement
- Case 333953: mistake in the sent invoice
- Case 366209: error in the received statement
- Case 404745: error in the received invoice
- Case 425177: error in the collected document
- Case 440377: improper information in the sent document
- Case 788701: incorrect information in the received receipt
- Case 802333: mistake in the accepted receipt
- Case 850033: improper information in the accepted statement
- Case 952590: incorrect information in the accepted document
- Case 956642: improper information in the received invoice
- Duplicated sent invoice #220020
- Lawsuit formed - missed payment #129746
- Lawsuit formed - missed payment #529257
- Lawsuit prepared - missed due payment #325133
- Lawsuit prepared - missed due payment #808480
- Lawsuit prepared - missed payment #970694
- Legal case formed - missed due payment #882677
- Legal case prepared - missed due payment #369678
- Legal case prepared - missed payment #332125
- Legal case prepared - missed payment #904032
- Monthly bill-#697717 tip
- Monthly bill-#957318 notification
- Recent invoice-#299841 reminder
- Recent invoice-#414650 notification
- Recent invoice-#781702 notice
- Recent invoice-#820597 tip
- Repeated given invoice #110156
- Repeated given invoice #229437
- Repeated invoice #498562
- Repeated sent invoice #202547
- Repeated sent invoice #625131
- Repeated sent invoice #897211
- Replicated given invoice #399436
- Replicated invoice #203648
- Replicated sent invoice #212693
- Requested invoice for agreement #194347
- Requested invoice for agreement #690316
- Requested invoice for contract #180327
- Requested payment invoice for agreement #265993
- Requested payment invoice for contract #382311
- The copy of given invoice #539735
- This is your Customer Invoice
- This is your New Invoice - Number #46344 from Ocean rover
- This is your Service Invoice from Phantasm Enterprises
- You have New incoming Invoice, No. # 98189 - from Shrub Industries
- Your New service Invoice - Number #92820
- Your Service Invoice Number #94618
- SENDERS OBSERVED
- abid.ricog1983@o2.pl
- alaf.mibut1986@o2.pl
- anis.imsmar1971@o2.pl
- atnis.adno1978@o2.pl
- bahla.gilgie1970@o2.pl
- beoloo.odos1988@o2.pl
- blasog.suni1977@o2.pl
- bucon.menha1988@o2.pl
- concu.noncu1973@o2.pl
- createv.asar1973@o2.pl
- diabrus.mata1983@o2.pl
- fasma.bnadland1985@o2.pl
- fichan.trantant1971@o2.pl
- flumta.joysweat1988@o2.pl
- gagnus.telilmaldurv@aol.com
- gbeatto.oriz1977@o2.pl
- georgiana_weitzner369@aol.com
- imbar.macre1984@o2.pl
- leman.abta1980@o2.pl
- lobsfi.coslde1984@o2.pl
- lytas.lighmont1976@o2.pl
- madball.rinsnis1982@o2.pl
- meamo.liosnar1974@o2.pl
- mwojap.taket1982@o2.pl
- necsea.angrok1985@o2.pl
- opet.harti1985@o2.pl
- patvi.biomang1974@o2.pl
- perchhigh.plotbio1976@o2.pl
- picca.antsys1977@o2.pl
- plegthinhorkc@aol.com
- poulriou.lesscou1979@o2.pl
- privag.mamar1978@o2.pl
- provin.tickprog1972@o2.pl
- repre.ilual1984@o2.pl
- ronma.seti1984@o2.pl
- sacla.pregov1978@o2.pl
- saso.quixa1987@o2.pl
- schadta.sfargood1977@o2.pl
- setto.taibrin1975@o2.pl
- sinus.anelendil19883@aol.com
- stenin.climuc1975@o2.pl
- stilar.rempwho1982@o2.pl
- stimen.marde1977@o2.pl
- stites.kiery1973@o2.pl
- taltough.crimgicz1978@o2.pl
- tatricminak142m@aol.com
- tbetom.procim1989@o2.pl
- tiona.goldsimp1977@o2.pl
- usci.dreamnia1986@o2.pl
- walthgytherogor1994o@aol.com
- walthrun.ruigora@aol.com
- woti.rilfi1974@o2.pl
- EXCEL FILE HASHES
- 002370067d30bcca116d15e81725d8c9
- 05cf8f988f8a49abb71d23df305741c9
- 06aaf31e8d3c9f81100ff36a0d859cb7
- 14753acba39910c010a04fd7553f6a53
- 202849e060957d650fea741ce9b4ce88
- 25034067c13b0a95172acf36b5165a5a
- 2774c65f65fbb96bbc2b7237ac51c34c
- 33bdad93680a057ba458bd8c7c87cfcd
- 39fad4e57aeb95eda7af991361c10f54
- 418d2d6f9784ddb574af8c821da7268e
- 42793c9bbc85c7d989235a5e0ef46d24
- 4de9e608b755ab948d5ea631f0758273
- 4feaa0fa06cbfd892d770a610f092a8f
- 516f4bea16a648f6f68be9cfb616b3d8
- 5381af760da498b8bab4167fbc3d748b
- 562b9bd07f7c1dbadc46bca7915c49b4
- 58e3f3100bb0f7e91bce1337d1320a42
- 5a17383e207ba4b3980cdc65c2dc4dd6
- 5cfc486736695c6df179170d4364d128
- 5d7bb3fceb01ac00cecf19975c518653
- 6782ef855e6ffa4b0e189a78ad8c9e26
- 7004e218042f73cddde6618e99b7666f
- 7d6df0560f107460bd280f54d33789b9
- 882170d60a116793448c9f9d561a5d25
- 8a756d99064a6e085bf3fdaf5c5d3f39
- 8b503094338ea8641a4cf66e1e5cb9b6
- 8e94dce713786a0d156ea90a6385ff66
- 902ae5a8d88e58e71635a61fd094fe2e
- 92d2859879257daa2b867bfa181d3a97
- 9970a3adf729e6f386ea9ba98a66caa9
- 9a8e50123598a2f9a25a052380b4adcd
- 9bdf039a4cedee368b996eea35f60903
- a32134ed1ae4b2ab7dbdf9ffece3de09
- a689cc39d0b340dbf9adccadfe2d8062
- a8f305e399eef7df8aef405e251f7ca5
- b6ab025b0610fe97b189c0cadf72e68b
- bfd5ac5017d3247d980768ff5d89564e
- c218b3fab7f7265b26d6051eaa64ef9d
- ce2631a0e4db424c504c271b6bd87670
- cf62ac48c30a1c99c220bd92bed6f8f9
- d28ffd304d53d13faee8b96efc28bf60
- d5253dbaaa9655595eeee2f78b49287d
- d623d87bb8bcb97a74fd4f37bc11b462
- d68f2443cb3565e55481e702a20a78be
- daf3f373828cb07079f79168950ee521
- dd313b17554bcf36ea952b6d7329eed3
- e5dff34fe3a3e2bb2ed2d7cd4986370f
- ed764924f77416cf1e54db108f5f3d92
- f3ea55683ae51f7073cd94c8571d0675
- f5422d1942790f66a895507d2738b7ae
- faf27ae79a86a47f52e224bf9ff9bb91
- ffef28c25512f2bf7e5f6188b7161bb4
- ZLOADER PAYLOAD URLs
- http://reneixer.org/wp/wp-content/themes/calliope/wp_data.php
- http://saidulhussen.com/wp-content/themes/calliope/wp-front.php
- http://sarkarjewells.com/wp-content/themes/calliope/wp-front.php
- http://semplyusya.ru/wp-content/themes/calliope/wp_data.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement