Skip to content

Conversation

@0ssigeno
Copy link
Contributor

Unfortunately there is a malware campaign in Italy that is using xls obfuscated macro.
The last version of https://github.com/DissectMalware/XLMMacroDeobfuscator, is able to deobfuscate the payload, allowing to correctly identify IOC.
image

@0ssigeno 0ssigeno force-pushed the xlm_macro_deobfuscator branch from bb31814 to 7f7433e Compare September 25, 2020 07:59
@0ssigeno 0ssigeno force-pushed the xlm_macro_deobfuscator branch from 7f7433e to 949542d Compare September 25, 2020 10:06
@0ssigeno 0ssigeno force-pushed the xlm_macro_deobfuscator branch from 949542d to acae65a Compare September 25, 2020 10:46
@eshaan7 eshaan7 merged commit 01b8102 into intelowlproject:develop Sep 25, 2020
@eshaan7
Copy link
Member

eshaan7 commented Sep 25, 2020

Thankyou for your contribution!

@mlodic mlodic mentioned this pull request Sep 28, 2020
@0ssigeno 0ssigeno deleted the xlm_macro_deobfuscator branch November 18, 2020 13:53
federicofantini pushed a commit that referenced this pull request Aug 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants